Junglewise Threat Intelligence

CVE-2026-46011: Linux Kernel MediaTek JPEG driver use-after-free in mtk_jpeg_release

CVE-2026-46011 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's MediaTek JPEG driver that could lead to a system crash or unauthorized memory access. The issue occurs when the system attempts to close a JPEG processing task while background work is still running, causing the software to access memory that has already been deleted. This could potentially be exploited by a local user to cause a denial-of-service (system crash) or potentially gain elevated privileges.

Technical details

A use-after-free (UAF) vulnerability exists in the mtk-jpeg driver within the Linux kernel's media subsystem. The root cause is located in the mtk_jpeg_release() function, which frees the context structure (ctx) without ensuring that pending or running work queued in ctx->jpeg_work has been cancelled. This creates a race condition where the workqueue callback (mtk_jpegenc_worker) may attempt to access the context memory after it has been deallocated by kfree(). An attacker with local access could trigger this race by closing the device file descriptor while a JPEG encoding or decoding operation is active. The fix involves calling cancel_work_sync() before acquiring the device mutex to ensure all background tasks are completed or terminated before the memory is freed.

Affected products

  • Linux Linux Kernel Fixed in 6.9 and various stable branches

Timeline

  • 2026-03-04: other: Patch authored
  • 2026-05-27: disclosed: CVE published
  • 2026-05-27: advisory: NVD advisory published

References