Use-after-free in Linux kernel - CVE-2026-46317
Published: June 10, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the nested_mmus array in arm64 KVM nested virtualization when reallocating nested MMU structures while the array is being walked under mmu_lock. A local user can trigger nested vcpu initialization and concurrent MMU notifier activity to cause a denial of service.
The issue arises from a race condition between nested vcpu initialization and the MMU notifier path.
Affected software
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
kernel (Red Hat package)
linux-azure-fde-6.17 (Ubuntu package)
linux-gcp-6.17 (Ubuntu package)
linux-oracle-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux (Ubuntu package)
linux-ibm (Ubuntu package)
linux-aws (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-46317
kernel (Red Hat package) - update to 6.12.0-211.61.1.el10_2
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-gcp-6.17 (Ubuntu package) - addressed in versions 6.17.0-1018.20~24.04.1, 6.17.0-1021.24~24.04.1
linux-oracle-6.17 (Ubuntu package) - addressed in versions 6.17.0-1019.19~24.04.3, 6.17.0-1019.19~24.04.3+1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1030.30
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1031.31
linux (Ubuntu package) - addressed in versions 7.0.0-28.28, 7.0.0-28.28.1, 7.0.0-1003.4, 7.0.0-1008.8
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1009.9
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
Related Security Bulletins
- Use-after-free in Linux kernel arm64 kvm
- Ubuntu update for linux-gcp-6.17
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux-oem-6.17
- Ubuntu update for linux-ibm
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-fde-6.17
- Ubuntu update for linux-azure-6.17
- Ubuntu update for linux-oracle-6.17
- Ubuntu update for linux-aws
- Ubuntu update for linux-nvidia-bos
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-nvidia-6.17
- Ubuntu update for linux-gcp-7.0
- Red Hat Enterprise Linux 10 update for kernel
- Ubuntu update for linux-oracle-7.0
- Ubuntu update for linux-azure-7.0