Out-of-bounds write in Linux kernel - CVE-2026-46281
Published: June 10, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in vrealloc_node_align_noprof() when reallocating and shrinking an existing vmalloc allocation that requires a new allocation. A local user can trigger the vulnerable reallocation path to cause a denial of service.
The issue occurs when the existing pointer is on the wrong NUMA node or does not satisfy an alignment constraint, causing data from the old allocation to be copied into a smaller new buffer.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-raspi (Ubuntu package)
How to mitigate CVE-2026-46281
linux (Ubuntu package) - update to 7.0.0-27.27
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13
linux-raspi (Ubuntu package) - update to 7.0.0-1014.14