PT-2026-47385 · Linux+2 · Linux Kernel+2

CVE-2026-46314

·

Published

2026-04-19

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A local user can cause an infinite loop in the kernel context by crafting a self-referential extension where ext->next == &ext with zero in sync count and out sync count. This occurs because the v3d get extensions() function processes a userspace-provided singly-linked list of ioctl extensions without bounding the chain length. The existing duplicate-extension guard is bypassed because v3d get multisync post deps() returns immediately when the count is zero, leaving both fields at zero during every iteration. This results in the calling thread being blocked and a CPU core being pegged indefinitely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-89639
BDU:2026-13887
CVE-2026-46314
ECHO-EED4-FA7C-5D6F
OPENSUSE-SU-2026:11014-1
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22809-1
SUSE-SU-2026:22810-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:22903-1
SUSE-SU-2026:22904-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8618-1
USN-8619-1
USN-8663-1
USN-8664-1
USN-8665-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu