๐Ÿ” CVE Alert

CVE-2026-46277

HIGH 7.8

mm/zone_device: do not touch device folio after calling ->folio_free()

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
3th

In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after calling ->folio_free() The contents of a device folio can immediately change after calling ->folio_free(), as the folio may be reallocated by a driver with a different order. Instead of touching the folio again to extract the pgmap, use the local stack variable when calling percpu_ref_put_many().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 8, 2026
Last Updated Jun 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
d245f9b4ab806733a77e51a218ca7b8bc3135cd9 < 85be0a262e39c706edb53c88af8afde2e98222ba d245f9b4ab806733a77e51a218ca7b8bc3135cd9 < 39928984956037cabd304321cb8f342e47421db5
Linux / Linux
6.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/85be0a262e39c706edb53c88af8afde2e98222ba git.kernel.org: https://git.kernel.org/stable/c/39928984956037cabd304321cb8f342e47421db5