PT-2026-47361 · Linux+2 · Linux Kernel+2
CVE-2026-46289
·
Published
2026-06-08
·
Updated
2026-09-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 6.3 through 6.5
Description
Issues exist in the
extract kvec to sg function within the scatterlist library. When extracting from a kvec to a scatterlist, the length for an sglist entry can exceed the number of bytes in the page by crossing page boundaries. Additionally, when extracting a user buffer, the sglist is used as a temporary scratch buffer for extracted page pointers; if the sglist already contains elements, this scratch buffer may overlap with existing entries.Recommendations
Update to version 6.5 or later to resolve the length calculation and buffer overlap issues.
Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu