Threats Tagged 'cve-2026-46316'
View all threats tagged with 'cve-2026-46316'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-46316'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.30. Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Security Fix(es): * kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316) * kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 07/21/2026, 15:21:16 UTC Added: 05/31/2026, 21:00:08 UTC |
Red Hat Security Advisory: kernel security updateCVE-2025-68183 0 The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/07/2026, 05:55:29 UTC Added: 07/18/2026, 11:34:05 UTC |
0 The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/06/2026, 14:33:52 UTC Added: 07/06/2026, 23:02:52 UTC |
0 This update includes the following RPMs: openssl-fips-provider: * openssl-fips-provider-3.0.7-1.2.hum1 (aarch64, x86_64) * openssl-fips-provider-so-3.0.7-1.2.hum1 (aarch64, x86_64) * openssl-fips-provider-3.0.7-1.2.hum1.src (src) Join the discussion | GCVE Database | 06/23/2026, 12:41:30 UTC Added: 05/27/2026, 21:15:26 UTC |
0 CVE-2026-46316 is a guest-to-host escape vulnerability in the vGIC-ITS emulation within KVM on ARM64 platforms. It is caused by a race condition in the vgic_its_invalidate_cache() function leading to a double-put use-after-free, which allows execution of code in the host kernel context. This flaw resides in the in-kernel KVM module, enabling successful exploitation to gain host kernel privileges. The vulnerability affects multi-tenant ARM64 cloud environments and can be chained with local privilege escalation when guest root access is unavailable. A patch fixing this vulnerability was applied in the Linux kernel at commit 13031fb6b835. Two YARA rules have been developed to detect exploitation attempts based on specific constants and behavioral patterns. There are no known exploits in the wild as of the latest information. Join the discussion | AlienVault OTX General | 06/12/2026, 16:57:58 UTC Added: 06/15/2026, 18:45:13 UTC |
A critical vulnerability in the Linux kernel's KVM arm64 vgic-its component was resolved. The issue involves improper handling of translation cache references during concurrent cache invalidation, leading to a use-after-free condition. This flaw could allow an attacker with local access to cause memory corruption with potential confidentiality, integrity, and availability impacts. Red Hat has issued security advisories providing patches for affected Red Hat Enterprise Linux 9 and 10 versions. Systems must be updated and rebooted to apply the fix. Join the discussion | GCVE Database | 06/09/2026, 15:32:17 UTC Added: 07/30/2026, 15:50:11 UTC |
A high-severity vulnerability (CVE-2026-46316) in the Linux kernel's KVM subsystem for ARM64 architecture was resolved. The flaw involved improper handling of the vgic-its translation cache references, leading to potential use-after-free conditions due to concurrent cache draining and reference dropping. This could result in memory corruption with high impact on confidentiality, integrity, and availability. The vulnerability affects multiple specific Linux kernel versions, primarily in the linux-hwe-edge product line. A patch is available and included in updated kernel versions. Users are advised to update and reboot to apply the fix. Join the discussion | GCVE Database | 06/09/2026, 13:16:00 UTC Added: 07/16/2026, 10:38:29 UTC |
0 The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653) * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366) * kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: Bluetooth: hci_sync: Fix UAF in le_read_features_complete (CVE-2026-43322) * kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions (CVE-2026-46243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/04/2026, 15:55:35 UTC Added: 05/29/2026, 21:02:27 UTC |
In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). For the epoll-watches-epoll case, f_op->release is ep_eventpoll_release() -> ep_clear_and_put() -> ep_free(), which kfree()s the watched struct eventpoll. Its embedded ->refs hlist_head is exactly where epi->fllink.pprev points, so the subsequent hlist_del_rcu()'s "*pprev = next" scribbles into freed kmalloc-192 memory. In addition, struct file is SLAB_TYPESAFE_BY_RCU, so the slot backing @file could be recycled by alloc_empty_file() -- reinitializing f_lock and f_ep -- while ep_remove() is still nominally inside that lock. The upshot is an attacker-controllable kmem_cache_free() against the wrong slab cache. Pin @file via epi_fget() at the top of ep_remove() and gate the critical section on the pin succeeding. With the pin held @file cannot reach refcount zero, which holds __fput() off and transitively keeps the watched struct eventpoll alive across the hlist_del_rcu() and the f_lock use, closing both UAFs. If the pin fails @file has already reached refcount zero and its __fput() is in flight. Because we bailed before clearing f_ep, that path takes the eventpoll_release() slow path into eventpoll_release_file() and blocks on ep->mtx until the waiter side's ep_clear_and_put() drops it. The bailed epi's share of ep->refcount stays intact, so the trailing ep_refcount_dec_and_test() in ep_clear_and_put() cannot free the eventpoll out from under eventpoll_release_file(); the orphaned epi is then cleaned up there. A successful pin also proves we are not racing eventpoll_release_file() on this epi, so drop the now-redundant re-check of epi->dying under f_lock. The cheap lockless READ_ONCE(epi->dying) fast-path bailout stays. Join the discussion | GCVE Database | 05/30/2026, 13:16:00 UTC Added: 07/17/2026, 10:19:12 UTC |
Showing 1 to 9 of 9 results