In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-IT…
Critical CVSS 9.3
Summary
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each entry with vgic_put_irq(). It puts the iterated pointer, though, rather than the value returned by xa_erase(). The function is called from contexts that do not exclude one another: the ITS command handlers hold its_lock,…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/13031fb6b8357fbbcded2a7f4cba73e4781ee594 Patch
- https://git.kernel.org/stable/c/2bbc395e81bd29c543a0529a678327e932a7ec69 Patch
- https://git.kernel.org/stable/c/9121f4605ab94969f62d1b5714ca3c6c69bd202f Patch
- https://git.kernel.org/stable/c/b7b72e88046328c9fdc638fe887d4240257dd5dc Patch
- https://access.redhat.com/errata/RHSA-2026:34911 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36018 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:38902
- https://access.redhat.com/errata/RHSA-2026:39371
- https://access.redhat.com/errata/RHSA-2026:40764
- https://access.redhat.com/errata/RHSA-2026:40779
- https://access.redhat.com/errata/RHSA-2026:40787
- https://access.redhat.com/security/cve/CVE-2026-46316 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2486982 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46316.json Third Party Advisory
Timeline
- nvd_ingest NVD