CVE-2026-46009

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown epf_ntb_epc_destroy() duplicates the teardown that the caller is supposed to do later. This leads to an oops when .allow_link fails or when .drop_link is performed. Remove the helper. Also drop pci_epc_put(). EPC device refcounting is tied to configfs EPC group lifetime, and pci_epc_put() in the .drop_link path is sufficient.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

16 Jun 2026, 15:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/3446beddba450c8d6f9aca2f028712ac527fead3 - () https://git.kernel.org/stable/c/3446beddba450c8d6f9aca2f028712ac527fead3 - Patch
References () https://git.kernel.org/stable/c/65fc57c8b8f0b31be62be291cb1bb01755cec85d - () https://git.kernel.org/stable/c/65fc57c8b8f0b31be62be291cb1bb01755cec85d - Patch
References () https://git.kernel.org/stable/c/72099f015d3c77bf2eb703d1aab113bd7a60915a - () https://git.kernel.org/stable/c/72099f015d3c77bf2eb703d1aab113bd7a60915a - Patch
References () https://git.kernel.org/stable/c/756ca5e7ed22d9045bb4de4c981f9149278d5cd3 - () https://git.kernel.org/stable/c/756ca5e7ed22d9045bb4de4c981f9149278d5cd3 - Patch
References () https://git.kernel.org/stable/c/c3029721b84f59e790285ad27544ed5d3cb0f2a6 - () https://git.kernel.org/stable/c/c3029721b84f59e790285ad27544ed5d3cb0f2a6 - Patch
References () https://git.kernel.org/stable/c/c72f6a7ea638f95c486a5cfd86e567b646027687 - () https://git.kernel.org/stable/c/c72f6a7ea638f95c486a5cfd86e567b646027687 - Patch
References () https://git.kernel.org/stable/c/e813c95e4c8edd31599081e6356e20ada30e266d - () https://git.kernel.org/stable/c/e813c95e4c8edd31599081e6356e20ada30e266d - Patch
CWE NVD-CWE-noinfo

01 Jun 2026, 17:17

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/c3029721b84f59e790285ad27544ed5d3cb0f2a6 -
  • () https://git.kernel.org/stable/c/c72f6a7ea638f95c486a5cfd86e567b646027687 -

27 May 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 14:17

Updated : 2026-06-17 10:52


NVD link : CVE-2026-46009

Mitre link : CVE-2026-46009

CVE.ORG link : CVE-2026-46009


JSON object : View

Products Affected

linux

  • linux_kernel