CVE-2026-46316
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/06/2026
Last modified:
23/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry<br />
<br />
vgic_its_invalidate_cache() walks the per-ITS translation cache with<br />
xa_for_each() and drops the cache&#39;s reference on each entry with<br />
vgic_put_irq(). It puts the iterated pointer, though, rather than the<br />
value returned by xa_erase().<br />
<br />
The function is called from contexts that do not exclude one another: the<br />
ITS command handlers hold its_lock, the GITS_CTLR write path holds<br />
cmd_lock, and the path that clears EnableLPIs in a redistributor&#39;s<br />
GICR_CTLR holds neither. Two or more of them can drain the same cache<br />
concurrently, and if each one observes the same entry, erases it and then<br />
puts it, the single reference the cache holds on that entry is dropped<br />
more than once. The entry can then be freed while an ITE still maps it.<br />
<br />
xa_erase() is atomic and returns the previous entry, so put only the entry<br />
that this context actually removed. The cache reference is then dropped<br />
exactly once per entry even when the invalidations run concurrently, and<br />
the behavior is unchanged when only one context runs.
Impact
Base Score 3.x
9.30
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.10 (including) | 6.12.93 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.35 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/13031fb6b8357fbbcded2a7f4cba73e4781ee594
- https://git.kernel.org/stable/c/2bbc395e81bd29c543a0529a678327e932a7ec69
- https://git.kernel.org/stable/c/9121f4605ab94969f62d1b5714ca3c6c69bd202f
- https://git.kernel.org/stable/c/b7b72e88046328c9fdc638fe887d4240257dd5dc
- https://access.redhat.com/errata/RHSA-2026:34911
- https://access.redhat.com/errata/RHSA-2026:36018
- https://access.redhat.com/errata/RHSA-2026:38902
- https://access.redhat.com/errata/RHSA-2026:39371
- https://access.redhat.com/errata/RHSA-2026:40764
- https://access.redhat.com/errata/RHSA-2026:40779
- https://access.redhat.com/errata/RHSA-2026:40787
- https://access.redhat.com/security/cve/CVE-2026-46316
- https://bugzilla.redhat.com/show_bug.cgi?id=2486982
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46316.json



