PT-2026-43961 · Linux+2 · Linux Kernel+2

CVE-2026-46093

·

Published

2026-05-27

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the Linux kernel within the decay va pool node() function. This function can be invoked concurrently by purge vmap area lazy() during pool purging and by the shrinker via vmap node shrink scan(). Because the shrinker path lacks proper serialization, concurrent execution can lead to races and potential memory leaks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-46093
OESA-2026-2582
OESA-2026-3157
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8569-1
USN-8603-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu