CVE-2026-46129
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix double free in create_space_info() error path
When kobject_init_and_add() fails, the call chain is:
create_space_info() -> btrfs_sysfs_add_space_info_type() -> kobject_init_and_add() -> failure -> kobject_put(&space_info->kobj) -> space_info_release() -> kfree(space_info)
Then control returns to create_space_info():
btrfs_sysfs_add_space_info_type() returns error -> goto out_free -> kfree(space_info)
This causes a double free.
Keep the direct kfree(space_info) for the earlier failure path, but after btrfs_sysfs_add_space_info_type() has called kobject_put(), let the kobject release callback handle the cleanup.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution60 %
Vulnerabilidad de double free (CWE-415) en kernel Linux accesible con privilegios locales (PR:L). Permite ejecutar código arbitrario o causar DoS elevando permisos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-415
Referencias
- https://git.kernel.org/stable/c/3f487be81292702a59ea9dbc4088b3360a50e837
- https://git.kernel.org/stable/c/9a060970fd7b5e1c561e4ce73cb9949e4269a738
- https://git.kernel.org/stable/c/ae6d6e31ceb72b7697c28a528e4923c08e3c2ef5
- https://git.kernel.org/stable/c/c2670ec4aa49ca226bce9776601e0da37502be07
- https://git.kernel.org/stable/c/dd6ade0fdd59218d71a981ae7c937a304e49209c
- https://git.kernel.org/stable/c/f414b3abbba59ef379a2b3c31f2bdd9358ed5e53
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-46129",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "20e8f2de3688082eeafeb93c8900485b7542457e",
"lessThan": "ae6d6e31ceb72b7697c28a528e4923c08e3c2ef5",
"versionType": "git"
},
{
"status": "affected",
"version": "58208907c4044a764dbd8896026283905da6d9be",
"lessThan": "c2670ec4aa49ca226bce9776601e0da37502be07",
"versionType": "git"
},
{
"status": "affected",
"version": "bb4fa4c0b54aae25e55faeda7f78d0c11b8cd618",
"lessThan": "f414b3abbba59ef379a2b3c31f2bdd9358ed5e53",
"versionType": "git"
},
{
"status": "affected",
"version": "6cb008f1bb23e023dfe615cca5df14570dfc8da5",
"lessThan": "9a060970fd7b5e1c561e4ce73cb9949e4269a738",
"versionType": "git"
},
{
"status": "affected",
"version": "a11224a016d6d1d46a4d9b6573244448a80d4d7f",
"lessThan": "dd6ade0fdd59218d71a981ae7c937a304e49209c",
"versionType": "git"
},
{
"status": "affected",
"version": "a11224a016d6d1d46a4d9b6573244448a80d4d7f",
"lessThan": "3f487be81292702a59ea9dbc4088b3360a50e837",
"versionType": "git"
},
{
"status": "affected",
"version": "6.1.162",
"lessThan": "6.1.175",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.122",
"lessThan": "6.6.140",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.67",
"lessThan": "6.12.88",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.7",
"lessThan": "6.18.30",
"versionType": "semver"
}
],
"programFiles": [
"fs/btrfs/space-info.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/btrfs/space-info.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-28T10:16:28.473",
"references": [
{
"url": "https://git.kernel.org/stable/c/3f487be81292702a59ea9dbc4088b3360a50e837",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9a060970fd7b5e1c561e4ce73cb9949e4269a738",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ae6d6e31ceb72b7697c28a528e4923c08e3c2ef5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c2670ec4aa49ca226bce9776601e0da37502be07",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dd6ade0fdd59218d71a981ae7c937a304e49209c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f414b3abbba59ef379a2b3c31f2bdd9358ed5e53",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Undergoing Analysis",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-415"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix double free in create_space_info() error path\n\nWhen kobject_init_and_add() fails, the call chain is:\n\ncreate_space_info()\n-> btrfs_sysfs_add_space_info_type()\n-> kobject_init_and_add()\n-> failure\n-> kobject_put(&space_info->kobj)\n-> space_info_release()\n-> kfree(space_info)\n\nThen control returns to create_space_info():\n\nbtrfs_sysfs_add_space_info_type() returns error\n-> goto out_free\n-> kfree(space_info)\n\nThis causes a double free.\n\nKeep the direct kfree(space_info) for the earlier failure path, but\nafter btrfs_sysfs_add_space_info_type() has called kobject_put(), let\nthe kobject release callback handle the cleanup."
}
],
"lastModified": "2026-06-24T18:10:24.650",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75727B5C-E260-40C6-ADB0-FE828902A5F7",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "6.1.162"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "511A93EB-D844-497A-8507-71BFE095FA06",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "6.6.122"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "251D1B2E-2F27-4042-84E8-B5A01A75AB74",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "6.12.67"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76CFFF82-D317-4BEA-807B-C59EA6680E3B",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "6.18.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4CB01CB-3218-4920-91CF-A5FFFFFF60C3",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "6.19.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35C8A871-4971-433E-A046-FC9F7B7D190A"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EF854A1-ABB1-4E93-BE9A-44569EC76C0D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5DC0CA6-F0AF-4DDF-A882-3DADB9A886A7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB5B7DFC-C36B-45D8-922C-877569FDDF43"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}