oM noM Security Feeds cve
vulnerability context

CVE-2026-46316

CVSS 9.3 CRITICALEPSS 10%OTX 8 pulses

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each entry with vgic_put_irq(). It puts the iterated pointer, though, rather than the value returned by xa_erase(). The function is called from contexts that do not exclude one another: the ITS command handlers hold its_lock, the GITS_CTLR write path holds cmd_lock, and the path that clears EnableLPIs in a redistributor's GI...

Published 2026-06-09 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
9.3 / CRITICAL
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
10% percentile (score 0.0020)
OTX pulses
8 total, 0 recent

source mentions 3

source consensus

  • Bluesky
  • oss-security
Want the 3-bullet summary of CVE-2026-46316, plus webhook alerts when KEV is updated? Pro is $10/mo.