Junglewise Threat Intelligence

CVE-2026-46316: Linux Kernel KVM use-after-free in arm64 vgic-its translation cache

CVE-2026-46316 · Severity: info · CVSS 5.5 · Published 2026-06-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's virtualization component for ARM64 systems. This flaw could allow a local user or guest system to cause a kernel crash or system instability by triggering a race condition during memory management. This impacts the reliability and availability of host systems running virtual machines.

Technical details

A race condition exists in vgic_its_invalidate_cache() within the Linux kernel's KVM ARM64 implementation. The function iterates through the translation cache and drops references to entries without ensuring exclusive access across different execution contexts (ITS command handlers, GITS_CTLR writes, and GICR_CTLR updates). Because multiple contexts could concurrently erase the same entry and drop its reference, the reference count could be decremented multiple times, leading to a use-after-free where an entry is freed while still mapped. The fix ensures that only the context that successfully performs the atomic xa_erase() operation drops the associated reference.

Affected products

  • Linux Linux kernel arm64 KVM vgic-its component

Timeline

  • 2026-06-01: other: Patch authored
  • 2026-06-09: disclosed: CVE published
  • 2026-06-09: patched: Fixes merged into stable branches

References

Related threats