CVE-2026-46317

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_lock kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which can run at any time. kvm_vcpu_init_nested() reallocates the array and frees the old buffer while holding only kvm->arch.config_lock, so such a walker can reference the freed array. Allocate the new array outside of mmu_lock, as the allocation can sleep. Under the lock, copy the existing entries, fix up the back pointers and reassign the array. Free the old buffer after dropping the lock, as kvfree() can sleep as well.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: KVM: arm64: Reasignar el array nested_mmus detrás de mmu_lock kvm->arch.nested_mmus[] es recorrido bajo kvm->mmu_lock, incluyendo desde la ruta del notificador de MMU (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), que puede ejecutarse en cualquier momento. kvm_vcpu_init_nested() reasigna el array y libera el búfer antiguo mientras mantiene solo kvm->arch.config_lock, por lo que dicho recorredor puede referenciar el array liberado. Asignar el nuevo array fuera de mmu_lock, ya que la asignación puede dormir. Bajo el bloqueo, copiar las entradas existentes, corregir los punteros inversos y reasignar el array. Liberar el búfer antiguo después de soltar el bloqueo, ya que kvfree() también puede dormir.

08 Jul 2026, 14:50

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/4424dbcb06d68e34e51c019a5781a7dc00731971 - () https://git.kernel.org/stable/c/4424dbcb06d68e34e51c019a5781a7dc00731971 - Patch
References () https://git.kernel.org/stable/c/70543358fa08e0f7cebc3447c3b70fe97ad7aaa8 - () https://git.kernel.org/stable/c/70543358fa08e0f7cebc3447c3b70fe97ad7aaa8 - Patch
References () https://git.kernel.org/stable/c/918450ad6010df6ecd2efde12a1409e011da22d6 - () https://git.kernel.org/stable/c/918450ad6010df6ecd2efde12a1409e011da22d6 - Patch
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*

14 Jun 2026, 06:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

09 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 13:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46317

Mitre link : CVE-2026-46317

CVE.ORG link : CVE-2026-46317


JSON object : View

Products Affected

linux

  • linux_kernel