PT-2026-43946 · Linux+2 · Linux Kernel+2

·

CVE-2026-46079

·

Published

2026-04-21

·

Updated

2026-08-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.11-1.1
Description A null-pointer dereference occurs in the rbd module when device add disk() fails after device add() has successfully published the device. In this scenario, the error path triggers a double teardown by calling rbd free disk() twice: once directly and again via rbd dev device release(). This inconsistent sequence leaves the blk-mq cleanup in an invalid state, leading to a crash in the blk mq free map and rqs() function, which is reached through blk mq free tag set(). The issue can be triggered when mapping an RBD image through the /sys/bus/rbd/add single major endpoint.
Recommendations Update the Linux kernel to version 7.0.11-1.1 or later.

Exploit

Fix

NULL Pointer Dereference

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88520
BDU:2026-13828
CVE-2026-46079
ECHO-D227-94E0-44D4
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu