CVE-2026-46189
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so calling it before triggers a double free.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.14%• Percentile: 4%
Techniques & Countermeasures
- CWE-415•Double Free
The product calls free() twice on the same memory address.
- CWE-1341•Multiple Releases of Same Resource or Handle
The product attempts to close or release a resource or handle more than once, without any successful open between the close operations.
Affected Systems
- linux•linux
≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < 269967d7693304e1f06ed2dff4ebbbeeb397cda4 | ≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < 1df5711121cdc11e76b889408fdbe459feba1d39 | ≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < 3a231c34c5bc3d3cfc850b877758ec9fdaa8a483 | ≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < ecc36a82ecfcfdf3c6606d209f22ec5543c410e0 | ≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < 45d25e3ec17900bf5a9d6876ff16ceee31c4c0e0 | ≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < 0c63333ff97bd1275294fd12840a0efe9d7a4c59 | ≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < 935ee27d0904aa944cbcc979094c20e5ef62eead | ≥ 29c8d9eba550c6d73d17cc1618a9f5f2a7345aa1, < e38e86995df27f1f854063dab1f0c6a513db3faf | 4.10
- linux•linux kernel
≥ 4.10, < 5.10.258 | ≥ 5.11, < 5.15.209 | ≥ 5.16, < 6.1.175 | ≥ 6.2, < 6.6.140 | ≥ 6.7, < 6.12.88 | ≥ 6.13, < 6.18.30 | ≥ 6.19, < 7.0.7 | 7.1:rc1 | 7.1:rc2
References (21)
- https://git.kernel.org/stable/c/ecc36a82ecfcfdf3c6606d209f22ec5543c410e0
- https://git.kernel.org/stable/c/45d25e3ec17900bf5a9d6876ff16ceee31c4c0e0
- https://git.kernel.org/stable/c/0c63333ff97bd1275294fd12840a0efe9d7a4c59
- https://git.kernel.org/stable/c/935ee27d0904aa944cbcc979094c20e5ef62eead
- https://git.kernel.org/stable/c/e38e86995df27f1f854063dab1f0c6a513db3faf
- https://git.kernel.org/stable/c/269967d7693304e1f06ed2dff4ebbbeeb397cda4
- https://git.kernel.org/stable/c/1df5711121cdc11e76b889408fdbe459feba1d39
- https://git.kernel.org/stable/c/3a231c34c5bc3d3cfc850b877758ec9fdaa8a483
- https://access.redhat.com/security/cve/CVE-2026-46189
- https://bugzilla.redhat.com/show_bug.cgi?id=2482588
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46189.json
- https://access.redhat.com/errata/RHSA-2026:30848
- https://access.redhat.com/errata/RHSA-2026:33685
- https://access.redhat.com/errata/RHSA-2026:36073
- https://access.redhat.com/errata/RHSA-2026:33743
- https://access.redhat.com/errata/RHSA-2026:36049
- https://access.redhat.com/errata/RHSA-2026:35904
- https://access.redhat.com/errata/RHSA-2026:36767
- https://access.redhat.com/errata/RHSA-2026:38902
- https://access.redhat.com/errata/RHSA-2026:40068
- https://access.redhat.com/errata/RHSA-2026:40760