Race condition in Linux kernel - CVE-2026-46135

 

Race condition in Linux kernel - CVE-2026-46135

Published: May 29, 2026


Vulnerability identifier: #VU133051
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46135
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a race condition in nvmet_tcp_handle_icreq() and target-side queue teardown when processing an initialization connection request and a connection close concurrently. A remote attacker can send an initialization connection request and immediately close the connection to cause a denial of service.

The issue can lead to a second kref_put() being issued on an already released queue.


Affected software

Linux kernel
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Ubuntu
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-devel
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
bpftool
kernel-headers
linux (Ubuntu package)
linux-ibm (Ubuntu package)
linux-raspi (Ubuntu package)
kernel-tools-debuginfo
python3-perf-debuginfo
kernel-tools-devel
perf-debuginfo
bpftool-debuginfo
kernel-source
kernel-debugsource
kernel-debuginfo
linux-xilinx-zynqmp (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
linux-nvidia (Ubuntu package)

How to mitigate CVE-2026-46135

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kernel (Red Hat package) - addressed in versions 4.18.0-305.199.1.el8_4, 4.18.0-372.201.1.el8_6, 4.18.0-553.136.1.el8_10, 5.14.0-284.179.1.el9_2, 5.14.0-427.139.1.el9_4, 5.14.0-570.127.1.el9_6, 5.14.0-687.17.1.el9_8, 6.12.0-55.88.1.el10_0, 6.12.0-211.28.1.el10_2
kernel-rt (Red Hat package) - addressed in versions 4.18.0-553.136.1.rt7.477.el8_10, 5.14.0-284.179.1.rt14.464.el9_2
kernel - update to 4.18.0-553.137.1.0.1
kernel-doc - update to 4.18.0-553.137.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.137.1.0.1
python3-perf - update to 4.18.0-553.137.1.0.1
perf - update to 4.18.0-553.137.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.137.1.0.1
kernel-tools-libs - update to 4.18.0-553.137.1.0.1
kernel-tools - update to 4.18.0-553.137.1.0.1
kernel-modules-extra - update to 4.18.0-553.137.1.0.1
kernel-modules - update to 4.18.0-553.137.1.0.1
kernel-devel - update to 4.18.0-553.137.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.137.1.0.1
kernel-debug-modules - update to 4.18.0-553.137.1.0.1
kernel-debug-devel - update to 4.18.0-553.137.1.0.1
kernel-debug-core - update to 4.18.0-553.137.1.0.1
kernel-debug - update to 4.18.0-553.137.1.0.1
kernel-cross-headers - update to 4.18.0-553.137.1.0.1
kernel-core - update to 4.18.0-553.137.1.0.1
bpftool - update to 4.18.0-553.137.1.0.1
kernel-headers - update to 4.18.0-553.137.1.0.1
linux (Ubuntu package) - addressed in versions 5.4.0.233.225, 5.4.0-233.253, 5.4.0-233.253~18.04.1, 5.4.0-1065.68, 5.4.0.1079.79, 5.4.0-1079.83, 5.4.0.1120.116, 5.4.0-1120.127, 5.4.0.1135.132, 5.4.0-1135.145, 5.4.0.1159.153, 5.4.0-1159.169+fips1, 5.4.0-1159.169~18.04.1, 5.4.0.1161.108, 5.4.0.1161.159, 5.4.0-1161.172, 5.4.0-1161.172+fips1, 5.4.0-1161.172~18.04.1, 5.4.0.1164.106, 5.4.0.1164.166, 5.4.0-1164.173, 5.4.0-1164.173+fips1, 5.4.0-1164.173~18.04.1, 5.4.0.1166.102, 5.4.0.1166.158, 5.4.0-1166.172, 5.4.0-1166.172+fips1, 5.4.0-1166.172~18.04.1, 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1, 6.17.0-40.40, 7.0.0-27.27
linux-ibm (Ubuntu package) - addressed in versions 5.4.0-1107.112, 5.4.0-1107.112~18.04.1, 5.4.0.1107.136
linux-raspi (Ubuntu package) - addressed in versions 5.4.0-1144.157, 5.4.0-1144.157~18.04.1, 5.4.0.1144.175, 5.15.0.1105.103, 5.15.0-1105.108, 6.8.0-1060.64, 6.17.0-1021.21, 7.0.0-1014.14
kernel-tools - update to 5.10.0-321.0.0.223
kernel-tools-debuginfo - update to 5.10.0-321.0.0.223
python3-perf-debuginfo - update to 5.10.0-321.0.0.223
kernel-tools-devel - update to 5.10.0-321.0.0.223
perf - update to 5.10.0-321.0.0.223
perf-debuginfo - update to 5.10.0-321.0.0.223
bpftool-debuginfo - update to 5.10.0-321.0.0.223
python3-perf - update to 5.10.0-321.0.0.223
kernel-source - update to 5.10.0-321.0.0.223
kernel-headers - update to 5.10.0-321.0.0.223
kernel-devel - update to 5.10.0-321.0.0.223
kernel-debugsource - update to 5.10.0-321.0.0.223
kernel-debuginfo - update to 5.10.0-321.0.0.223
kernel - update to 5.10.0-321.0.0.223
bpftool - update to 5.10.0-321.0.0.223
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1029.30
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1, 7.0.0-1009.9, 7.0.0-1010.10
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13

External References

Related Security Bulletins