Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path

Sashiko points out that pvrdma_uar_free() is already called within
pvrdma_dealloc_ucontext(), so calling it before triggers a double free.
Published: 2026-05-28
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel instability leading to potential crash or denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a double free within the Linux kernel’s RDMA/pvrdma driver, triggered when pvrdma_uar_free() is called twice on the same context. This kernel memory corruption can cause a kernel panic or other instability, resulting in a denial of service if an attacker can execute the error path.

Affected Systems

All Linux kernel versions before the inclusion of the fix commit as listed in the kernel source. The flaw resides within the RDMA/pvrdma driver included in the standard Linux kernel distribution.

Risk and Exploitability

Because the issue is a kernel-level double free, an attacker who can trigger the error path—most likely through crafted RDMA traffic or a local privileged context—may cause a crash. The EPSS score of < 1% and the CVSS score of 7.8 indicate low probability of spontaneous exploitation, and the vulnerability is not listed in CISA KEV. Nevertheless, the potential for a kernel crash justifies prompt action.

Generated by OpenCVE AI on September 10, 2026 at 05:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the patch from commit 0c63333ff97bd1275294fd12840a0efe9d7a4c59, or apply the corresponding backport if using an older distribution.
  • If an immediate upgrade is not possible, disable the RDMA/pvrdma driver or block RDMA traffic to prevent accidental activation of the vulnerable code path.
  • Regularly review kernel release notes and security advisories to ensure the fix is applied before the kernel is deployed in production environments.

Generated by OpenCVE AI on September 10, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4664-1 linux security update
Debian DLA Debian DLA DLA-4665-1 linux security update
Debian DLA Debian DLA DLA-4671-1 linux-6.1 security update
Ubuntu USN Ubuntu USN USN-8566-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8567-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8568-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8569-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-1 Linux kernel (GCP FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8575-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8576-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8596-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8575-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8576-2 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8597-1 Linux kernel (IBM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8575-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-2 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8608-1 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8610-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-2 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-3 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-4 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-8663-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8664-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8665-1 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8668-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8668-2 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-2 Linux kernel (Azure) vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:30848 cve-icon
https://access.redhat.com/errata/RHSA-2026:33685 cve-icon
https://access.redhat.com/errata/RHSA-2026:33743 cve-icon
https://access.redhat.com/errata/RHSA-2026:35904 cve-icon
https://access.redhat.com/errata/RHSA-2026:36049 cve-icon
https://access.redhat.com/errata/RHSA-2026:36073 cve-icon
https://access.redhat.com/errata/RHSA-2026:36767 cve-icon
https://access.redhat.com/errata/RHSA-2026:38902 cve-icon
https://access.redhat.com/errata/RHSA-2026:40068 cve-icon
https://access.redhat.com/errata/RHSA-2026:40760 cve-icon
https://access.redhat.com/errata/RHSA-2026:47633 cve-icon
https://access.redhat.com/security/cve/CVE-2026-46189 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2482588 cve-icon
https://git.kernel.org/stable/c/0c63333ff97bd1275294fd12840a0efe9d7a4c59 cve-icon cve-icon
https://git.kernel.org/stable/c/1df5711121cdc11e76b889408fdbe459feba1d39 cve-icon cve-icon
https://git.kernel.org/stable/c/269967d7693304e1f06ed2dff4ebbbeeb397cda4 cve-icon cve-icon
https://git.kernel.org/stable/c/3a231c34c5bc3d3cfc850b877758ec9fdaa8a483 cve-icon cve-icon
https://git.kernel.org/stable/c/45d25e3ec17900bf5a9d6876ff16ceee31c4c0e0 cve-icon cve-icon
https://git.kernel.org/stable/c/935ee27d0904aa944cbcc979094c20e5ef62eead cve-icon cve-icon
https://git.kernel.org/stable/c/e38e86995df27f1f854063dab1f0c6a513db3faf cve-icon cve-icon
https://git.kernel.org/stable/c/ecc36a82ecfcfdf3c6606d209f22ec5543c410e0 cve-icon cve-icon
https://lore.kernel.org/linux-cve-announce/2026052831-CVE-2026-46189-c188@gregkh/T cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-46189 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46189.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-46189 cve-icon
History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-763

Thu, 11 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
CPEs cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 01 Jun 2026 17:00:00 +0000


Fri, 29 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1341
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 28 May 2026 10:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so calling it before triggers a double free.
Title RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-09T12:04:49.181Z

Reserved: 2026-05-13T15:03:33.104Z

Link: CVE-2026-46189

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-05-28T10:16:34.540

Modified: 2026-09-09T13:20:16.377

Link: CVE-2026-46189

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-28T00:00:00Z

Links: CVE-2026-46189 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:45:06Z

Weaknesses
  • CWE-1341

    Multiple Releases of Same Resource or Handle

  • CWE-415

    Double Free

  • CWE-763

    Release of Invalid Pointer or Reference