CVE-2026-46162

Source
https://cve.org/CVERecord?id=CVE-2026-46162
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46162.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46162
Downstream
Related
Published
2026-05-28T09:36:17Z
Modified
2026-08-12T03:30:19Z
Summary
ice: fix double free in ice_sf_eth_activate() error path
Details

In the Linux kernel, the following vulnerability has been resolved:

ice: fix double free in ice_sf_eth_activate() error path

When auxiliary_device_add() fails, ice_sf_eth_activate() jumps to aux_dev_uninit and calls auxiliary_device_uninit(&sf_dev->adev).

The device release callback ice_sf_dev_release() frees sf_dev, but the current error path falls through to sf_dev_free and calls kfree(sf_dev) again, causing a double free.

Keep kfree(sf_dev) for the auxiliary_device_init() failure path, but avoid falling through to sf_dev_free after auxiliary_device_uninit().

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46162.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
13acc5c4cdbeccf3274cbbd4de2e2d316b8c4ce6
Fixed
2ca30340b5028ddc3f17086a538feeff06167b1b
Fixed
121d1f253aed515cd85748f68c664a6cb756e8ad
Fixed
d0c6a4816609f145ffcc74e64baa214c571c17c6
Fixed
9aab1c3d7299285e2569cbc0ed5892d631a241b2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46162.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.88
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.30
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46162.json"