Junglewise Threat Intelligence

CVE-2026-46118: Linux Kernel NULL pointer dereference in pseries papr-hvpipe

CVE-2026-46118 · Severity: info · CVSS 6.2 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's pseries platform support could allow a local user to crash the system. The issue occurs in the PAPR hypervisor pipe driver, which manages communication channels on IBM Power Systems. An exploit would result in a kernel panic (system crash), leading to a complete loss of availability for the affected server.

Technical details

A NULL pointer dereference exists in the papr_hvpipe_dev_create_handle() function within the pseries/papr-hvpipe driver. The vulnerability was introduced by a change to use the FD_PREPARE() macro, which incorrectly handled the 'src_info' pointer by nullifying it before it was reused for list operations. A local attacker with access to the papr-hvpipe device could trigger this by invoking specific ioctl calls, resulting in a kernel panic. The fix involves restructuring the allocation and list management logic to ensure pointers remain valid during the handle creation process. Patches have been released for various stable kernel branches.

Affected products

  • Linux Linux Kernel pseries/papr-hvpipe component

Timeline

  • 2026-05-01: patched: Initial fix commit 1b9f7aafa44f5ce852c00509104d10fd9eb0f402 authored
  • 2026-05-28: advisory: NVD publication date

References