PT-2026-43903 · Linux+1 · Linux Kernel+1

CVE-2026-46036

·

Published

2026-05-27

·

Updated

2026-08-12

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.11-1.1
Description A use-after-free issue exists in the vfio/cdx component. The function vfio cdx set msi trigger() reads vdev->config msi and operates on the vdev->cdx irqs array without proper serialization against concurrent VFIO DEVICE SET IRQS ioctls. This allows a race condition where one caller observes config msi as set while another caller clears it and frees the cdx irqs array via vfio cdx msi disable(), leading to a use-after-free of the cdx irqs array.
Recommendations Update to version 7.0.11-1.1.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46036
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8569-1
USN-8603-1

Affected Products

Linux Kernel
Ubuntu