« Volver al listado

CVE-2026-46281

Estado: AnalizadaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

vmalloc: fix buffer overflow in vrealloc_node_align()

Commit 4c5d3365882d ("mm/vmalloc: allow to set node and align in vrealloc") added the ability to force a new allocation if the current pointer is on the wrong NUMA node, or if an alignment constraint is not met, even if the user is shrinking the allocation.

On this path (need_realloc), the code allocates a new object of 'size' bytes and then memcpy()s 'old_size' bytes into it. If the request is to shrink the object (size < old_size), this results in an out-of-bounds write on the new buffer.

Leer descripción completaMostrar menos

Fix this by bounding the copy length by the new allocation size.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Buffer overflow local (AV:L,PR:L) en kernel Linux vrealloc_node_align permite escalada de privilegios (CAP:I:H). Impacto: ejecución de código en kernel (T1059) o DoS por corrupción de memoria.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-46281",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4c5d3365882dbbc0784688784904f440d7a4c0f1",
              "lessThan": "e9b057a44deff4c59c13f44672a5cc74dcd57522",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4c5d3365882dbbc0784688784904f440d7a4c0f1",
              "lessThan": "b281adf71f786c325eb6d6d1582d4d05313438a8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4c5d3365882dbbc0784688784904f440d7a4c0f1",
              "lessThan": "82d1f01292d3f09bf063f829f8ab8de12b4280a1",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/vmalloc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.27",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/vmalloc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-08T17:16:45.817",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/82d1f01292d3f09bf063f829f8ab8de12b4280a1",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b281adf71f786c325eb6d6d1582d4d05313438a8",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e9b057a44deff4c59c13f44672a5cc74dcd57522",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvmalloc: fix buffer overflow in vrealloc_node_align()\n\nCommit 4c5d3365882d (\"mm/vmalloc: allow to set node and align in\nvrealloc\") added the ability to force a new allocation if the current\npointer is on the wrong NUMA node, or if an alignment constraint is not\nmet, even if the user is shrinking the allocation.\n\nOn this path (need_realloc), the code allocates a new object of 'size'\nbytes and then memcpy()s 'old_size' bytes into it.  If the request is to\nshrink the object (size < old_size), this results in an out-of-bounds\nwrite on the new buffer.\n\nFix this by bounding the copy length by the new allocation size."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nvmalloc: corregir desbordamiento de búfer en vrealloc_node_align()\n\nEl commit 4c5d3365882d ('mm/vmalloc: permitir establecer nodo y alineación en vrealloc') añadió la capacidad de forzar una nueva asignación si el puntero actual está en el nodo NUMA incorrecto, o si no se cumple una restricción de alineación, incluso si el usuario está reduciendo la asignación.\n\nEn esta ruta (need_realloc), el código asigna un nuevo objeto de 'size' bytes y luego copia 'old_size' bytes en él usando memcpy(). Si la solicitud es reducir el objeto (size < old_size), esto resulta en una escritura fuera de límites en el nuevo búfer.\n\nSolucionar esto limitando la longitud de la copia por el nuevo tamaño de asignación."
    }
  ],
  "lastModified": "2026-07-23T08:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A10DA86-4154-4102-9D63-807CF10A4352",
              "versionEndExcluding": "6.18.27",
              "versionStartIncluding": "6.18"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDB78D6D-22C3-4154-B0D0-94AF1CE5C2E3",
              "versionEndExcluding": "7.0.4",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}