Eventpoll Memory Management Flaw in Linux Kernel
CVE-2026-46242
What is CVE-2026-46242?
A memory management vulnerability in the Linux kernel's eventpoll subsystem allows for a misuse of freed memory, resulting from improper handling of file structures during critical operations. The flaw occurs when an ep_remove operation clears a file pointer under lock while allowing concurrent operations to be performed on the same pointer. This leads to a potential use-after-free scenario where attackers could exploit the vulnerability to manipulate memory, potentially causing system instability or unauthorized access. The resolution involves implementing better reference management to prevent premature memory release during critical operations.
Affected Version(s)
Linux 58c9b016e12855286370dfb704c08498edbc857a
Linux 58c9b016e12855286370dfb704c08498edbc857a
Linux 58c9b016e12855286370dfb704c08498edbc857a