Junglewise Threat Intelligence

CVE-2026-46147: Linux Kernel KVM memory leak and race condition in arm64 vCPU init

CVE-2026-46147 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component (KVM) for ARM64 systems could allow a local attacker to cause memory leaks or observe partially initialized virtual machine components. This affects systems using Protected KVM (pKVM), potentially leading to resource exhaustion or unstable system behavior. The issue has been resolved in recent kernel updates.

Technical details

Two distinct issues were identified in the __pkvm_init_vcpu() function of the Linux kernel's ARM64 KVM implementation. First, a logic error in the error-handling path failed to unpin host vCPU and SVE state pages if a check failed after successful pinning, resulting in a permanent reference leak. Second, a lack of proper memory barriers allowed a concurrent caller of pkvm_load_hyp_vcpu() to observe a vCPU pointer before the underlying object was fully initialized. The fix introduces a register_hyp_vcpu() helper to ensure proper cleanup on failure and utilizes smp_store_release() and smp_load_acquire() to enforce correct publication ordering.

Affected products

  • Linux Linux Kernel 6.14, 6.15, 6.16

Timeline

  • 2026-04-24: patched: Initial patch submitted to the kernel tree.
  • 2026-05-28: disclosed: CVE-2026-46147 published.

References