PT-2026-46022 · Linux+3 · Linux Kernel+3

CVE-2026-46259

·

Published

2026-01-28

·

Updated

2026-08-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the procfs component of the Linux kernel within the do task stat() function. When reading the '/proc/[pid]/stat' endpoint, the system accesses the real parent variable without adequate Read-Copy Update (RCU) protection. RCU is a synchronization mechanism that allows multiple readers to access data while it is being updated. This lack of protection can lead to a Use-After-Free (UAF) condition, which occurs when a program continues to use a pointer after the memory it points to has been freed, potentially causing system instability or crashes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36018
ALSA-2026:36348
ALSA-2026:36349
ALSA-2026:36541
BDU:2026-11805
CVE-2026-46259
LSN-0121-1
OESA-2026-2673
OESA-2026-2674
OESA-2026-2675
OPENSUSE-SU-2026:21388-1
RHSA-2026:36018
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2450-1
SUSE-SU-2026:2722-1
SUSE-SU-2026:2799-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu