{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-46058","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-05-13T15:03:33.095Z","datePublished":"2026-05-27T12:57:17.853Z","dateUpdated":"2026-08-05T12:29:25.621Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:29:25.621Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: amphion: Fix race between m2m job_abort and device_run\n\nFix kernel panic caused by race condition where v4l2_m2m_ctx_release()\nfrees m2m_ctx while v4l2_m2m_try_run() is about to call device_run\nwith the same context.\n\nRace sequence:\n  v4l2_m2m_try_run():           v4l2_m2m_ctx_release():\n    lock/unlock                   v4l2_m2m_cancel_job()\n                                    job_abort()\n                                      v4l2_m2m_job_finish()\n                                  kfree(m2m_ctx)  <- frees ctx\n    device_run()  <- use-after-free crash at 0x538\n\nCrash trace:\n  Unable to handle kernel read from unreadable memory at virtual address\n  0000000000000538\n  v4l2_m2m_try_run+0x78/0x138\n  v4l2_m2m_device_run_work+0x14/0x20\n\nThe amphion vpu driver does not rely on the m2m framework's device_run\ncallback to perform encode/decode operations.\n\nFix the race by preventing m2m framework job scheduling entirely:\n- Add job_ready callback returning 0 (no jobs ready for m2m framework)\n- Remove job_abort callback to avoid the race condition"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The amphion VPU is a V4L2 mem2mem device reached only through a local `/dev/videoN` device file via open/ioctl/close; there is no network or remote path to this code.\nAC:L - The flaw is a race the attacker fully controls by running one thread that streams/queues buffers (scheduling a job) and another that closes the fd (triggering release); it can be retried in a loop until won.\nPR:L - Exploitation requires a local unprivileged user with access to the V4L2 device node (typically granted via the video group or logged-in session ACL); no root is needed.\nUI:N - The attacker performs all steps (open, stream, concurrent close) itself; no action by any other user is required.\nS:U - The vulnerability and its impact are confined to the kernel's own security authority with no crossing of a VM/IOMMU/sandbox boundary.\nC:H - The freed `m2m_ctx` is dereferenced after `kfree` (use-after-free per the fix), and a UAF over a slab object the attacker can groom/reallocate is treated as enabling arbitrary read of freed contents.\nI:H - The use-after-free on the freed context permits heap grooming/reallocation of the object that is then dereferenced, providing a write/control primitive consistent with kernel UAF integrity impact.\nA:H - The race reliably faults on an invalid pointer in `v4l2_m2m_try_run`, producing a kernel oops/panic and denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/platform/amphion/vpu_v4l2.c"],"versions":[{"version":"3cd084519c6f91cbef9d604bcf26844fa81d4922","lessThan":"516467052fdfc6a13eadc70d43420ae57436bf3c","status":"affected","versionType":"git"},{"version":"3cd084519c6f91cbef9d604bcf26844fa81d4922","lessThan":"42dc622776f3ce1a6c31b13bdc686f7295e3b323","status":"affected","versionType":"git"},{"version":"3cd084519c6f91cbef9d604bcf26844fa81d4922","lessThan":"da4f46c5cf1d26e6b09418ad453e152f2e75a02c","status":"affected","versionType":"git"},{"version":"3cd084519c6f91cbef9d604bcf26844fa81d4922","lessThan":"fdc150dac1adb9a98be9d6956cff0348838b024a","status":"affected","versionType":"git"},{"version":"3cd084519c6f91cbef9d604bcf26844fa81d4922","lessThan":"6be2cb75bc1300080cfc8051579f22efae9401f7","status":"affected","versionType":"git"},{"version":"3cd084519c6f91cbef9d604bcf26844fa81d4922","lessThan":"8cd35ceadcfc8c5da2eb7f7ce24525ce9d4ee62e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/media/platform/amphion/vpu_v4l2.c"],"versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.140","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.86","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.27","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.4","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.6.140"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.12.86"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.18.27"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.0.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/516467052fdfc6a13eadc70d43420ae57436bf3c"},{"url":"https://git.kernel.org/stable/c/42dc622776f3ce1a6c31b13bdc686f7295e3b323"},{"url":"https://git.kernel.org/stable/c/da4f46c5cf1d26e6b09418ad453e152f2e75a02c"},{"url":"https://git.kernel.org/stable/c/fdc150dac1adb9a98be9d6956cff0348838b024a"},{"url":"https://git.kernel.org/stable/c/6be2cb75bc1300080cfc8051579f22efae9401f7"},{"url":"https://git.kernel.org/stable/c/8cd35ceadcfc8c5da2eb7f7ce24525ce9d4ee62e"}],"title":"media: amphion: Fix race between m2m job_abort and device_run","x_generator":{"engine":"bippy-1.2.0"}}}}