CVE-2026-46289
A flaw in the Linux kernel's memory management code allows for incorrect length calculations when moving data. This can cause data to be written past the intended boundaries of a memory page.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Linux kernel versions 6.3 and later, specifically those where the affected function was moved to lib/scatterlist.c (v6.5+).
Real-world impact
An attacker could potentially cause system instability or memory corruption by triggering incorrect memory length calculations, potentially leading to unauthorized access or system crashes.
Why this severity
The critical score reflects that this vulnerability is easy to exploit remotely without authentication and can lead to a total loss of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the Linux kernel to version 6.5 or later to include the fix for lib/scatterlist.c.
NVD-referenced vendor advisory
Timeline
- Jun 8, 2026 · Jun 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.