cbcvebase.
CVE-2026-46281
published 2026-06-08

CVE-2026-46281: In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix buffer overflow in vrealloc_node_align() Commit 4c5d3365882d ("mm/vmalloc…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.9th percentile
In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix buffer overflow in vrealloc_node_align() Commit 4c5d3365882d ("mm/vmalloc: allow to set node and align in vrealloc") added the ability to force a new allocation if the current pointer is on the wrong NUMA node, or if an alignment constraint is not met, even if the user is shrinking the allocation. On this path (need_realloc), the code allocates a new object of 'size' bytes and then memcpy()s 'old_size' bytes into it. If the request is to shrink the object (size < old_size), this results in an out-of-bounds write on the new buffer. Fix this by bounding the copy length by the new allocation size.

Affected

20 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 4c5d3365882dbbc0784688784904f440d7a4c0f1 < e9b057a44deff4c59c13f44672a5cc74dcd57522e9b057a44deff4c59c13f44672a5cc74dcd57522
linuxlinux>= 4c5d3365882dbbc0784688784904f440d7a4c0f1 < b281adf71f786c325eb6d6d1582d4d05313438a8b281adf71f786c325eb6d6d1582d4d05313438a8
linuxlinux>= 4c5d3365882dbbc0784688784904f440d7a4c0f1 < 82d1f01292d3f09bf063f829f8ab8de12b4280a182d1f01292d3f09bf063f829f8ab8de12b4280a1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.18 < 6.18.276.18.27
linuxlinux_kernel>= 6.19 < 7.0.47.0.4
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-fde
ubuntulinux-gcp
ubuntulinux-hwe-7.0
ubuntulinux-ibm
ubuntulinux-nvidia
ubuntulinux-oem-7.0
ubuntulinux-oracle
ubuntulinux-raspi
ubuntulinux-realtime

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.