Junglewise Threat Intelligence

CVE-2026-46187: Linux Kernel RSI Wi-Fi driver use-after-free in kthread management

CVE-2026-46187 · Severity: info · CVSS 5.5 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's RSI Wi-Fi driver that could lead to a system crash. The issue occurs during specific shutdown sequences of the wireless driver, where internal processes conflict and attempt to access memory that has already been cleared. This could allow a local user to cause a denial-of-service (system instability or crash).

Technical details

A use-after-free (UAF) vulnerability exists in the RSI Wi-Fi driver within the Linux kernel. The root cause is a race condition in kthread management where both kthread_complete_and_exit() (self-exit) and kthread_stop() (external-stop) are utilized. In rare scenarios where the thread exits itself before the external stop command is processed, the kernel attempts to access the already-freed kthread object. This is resolved by removing the kthread_stop() call in favor of waiting for completion of the self-exit operation. The vulnerability was discovered via syzbot and affects systems using RSI wireless hardware.

Affected products

  • Linux Linux Kernel Fixed in versions 16d9f67, 4f4c9b1, 4f9a4ae, 95fcb43, db57a1a

Timeline

  • 2026-04-23: patched: Initial patch authored by Jeongjun Park
  • 2026-05-28: disclosed: CVE published to NVD dataset

References