Improper input validation in Linux kernel - CVE-2026-46314
Published: June 10, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in v3d_get_extensions() and multisync extension handling in the v3d driver when processing a userspace-provided ioctl extension list. A local user can submit a self-referential extension with zero in_sync_count and out_sync_count to cause a denial of service.
The issue can result in an infinite loop in kernel context that blocks the calling thread and pegs a CPU core indefinitely.