CVE-2026-46316

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry<br /> <br /> vgic_its_invalidate_cache() walks the per-ITS translation cache with<br /> xa_for_each() and drops the cache&amp;#39;s reference on each entry with<br /> vgic_put_irq(). It puts the iterated pointer, though, rather than the<br /> value returned by xa_erase().<br /> <br /> The function is called from contexts that do not exclude one another: the<br /> ITS command handlers hold its_lock, the GITS_CTLR write path holds<br /> cmd_lock, and the path that clears EnableLPIs in a redistributor&amp;#39;s<br /> GICR_CTLR holds neither. Two or more of them can drain the same cache<br /> concurrently, and if each one observes the same entry, erases it and then<br /> puts it, the single reference the cache holds on that entry is dropped<br /> more than once. The entry can then be freed while an ITE still maps it.<br /> <br /> xa_erase() is atomic and returns the previous entry, so put only the entry<br /> that this context actually removed. The cache reference is then dropped<br /> exactly once per entry even when the invalidations run concurrently, and<br /> the behavior is unchanged when only one context runs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.10 (including) 6.12.93 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.35 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.12 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*