PT-2026-43942 · Linux+2 · Linux Kernel+2

CVE-2026-46075

·

Published

2026-03-14

·

Updated

2026-08-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.11-1.1
Description A Use-After-Free (UAF) and memory leak issue exists in the atmel-sha204a crypto component. The problem occurs during the device removal process if the Atmel I2C workqueue is not flushed before teardown, potentially allowing a queued callback to execute while the device is being removed. Additionally, an early return in the removal path prevents the deletion of sysfs entries and the freeing of hwrng.priv, leading to a memory leak.
Recommendations Update to version 7.0.11-1.1.

Exploit

Fix

Memory Leak

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88647
BDU:2026-14217
CVE-2026-46075
ECHO-2609-8708-04A3
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu