CVE-2026-46058

HIGH EPSS 0.9%
Published May 27, 20261mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published May 27, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: media: amphion: Fix race between m2m job_abort and device_run Fix kernel panic caused by race condition where v4l2_m2m_ctx_release() frees m2m_ctx while v4l2_m2m_try_run() is about to call device_run with the same context. Race sequence: v4l2_m2m_try_run(): v4l2_m2m_ctx_release(): lock/unlock v4l2_m2m_cancel_job() job_abort() v4l2_m2m_job_finish() kfree(m2m_ctx) <- frees ctx device_run() <- use-after-free crash at 0x538 Crash trace: Unable to handle kernel read from unreadable memory at virtual address 0000000000000538 v4l2_m2m_try_run+0x78/0x138 v4l2_m2m_device_run_work+0x14/0x20 The amphion vpu driver does not rely on the m2m framework's device_run callback to perform encode/decode operations. Fix the race by preventing m2m framework job scheduling entirely: - Add job_ready callback returning 0 (no jobs ready for m2m framework) - Remove job_abort callback to avoid the race condition

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
0.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-362

Affected Products 5

VendorProductVersionRange
linuxlinux_kernel*≥5.18  –  <6.1.175
linuxlinux_kernel*≥6.2  –  <6.6.140
linuxlinux_kernel*≥6.7  –  <6.12.86
linuxlinux_kernel*≥6.13  –  <6.18.27
linuxlinux_kernel*≥6.19  –  <7.0.4

References 6

  • git.kernel.org https://git.kernel.org/stable/c/42dc622776f3ce1a6c31b13bdc686f7295e3b323
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/516467052fdfc6a13eadc70d43420ae57436bf3c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6be2cb75bc1300080cfc8051579f22efae9401f7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8cd35ceadcfc8c5da2eb7f7ce24525ce9d4ee62e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/da4f46c5cf1d26e6b09418ad453e152f2e75a02c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fdc150dac1adb9a98be9d6956cff0348838b024a
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/42dc622776f3ce1a6c31b13bdc686f7295e3b323
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/516467052fdfc6a13eadc70d43420ae57436bf3c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6be2cb75bc1300080cfc8051579f22efae9401f7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8cd35ceadcfc8c5da2eb7f7ce24525ce9d4ee62e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/da4f46c5cf1d26e6b09418ad453e152f2e75a02c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fdc150dac1adb9a98be9d6956cff0348838b024a
    Patch