Junglewise Threat Intelligence

CVE-2026-46021: Linux Kernel use-after-free and memory leak in thermal core

CVE-2026-46021 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's thermal management system could allow a local attacker to cause system instability or a crash. The issue stems from how the system handles the registration and removal of thermal zones, which manage hardware temperature. If these processes are interrupted or occur simultaneously, it can lead to memory errors that compromise the reliability of the operating system.

Technical details

Two distinct issues exist in the Linux kernel thermal core. First, a memory leak occurs if thermal_zone_device_register_with_trips() fails after a governor has been added but before registration is complete, as the governor is not properly removed. Second, a use-after-free vulnerability exists in thermal_zone_device_unregister() because it calls thermal_set_governor() without acquiring the necessary thermal zone lock. This creates a race condition with governor updates initiated via sysfs. The fix involves moving thermal_set_governor() calls to thermal_release() and adding them to the registration error path to ensure proper synchronization and cleanup.

Affected products

  • Linux Linux Kernel All versions prior to the fix (specifically affecting thermal core)

Timeline

  • 2026-04-07: patched: Initial patch authored by Rafael J. Wysocki
  • 2026-05-27: advisory: NVD advisory published

References