CVE-2026-46171: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: riscv: kvm: fix vector context allocation leak When the second kzalloc (host_context.vector.datap) fails in kvm_riscv_vcpu_alloc_vector_context, the first allocation (guest_context.vector.datap) is leaked. Free it before returning.
Affected products
- Linux Linux Kernel: from 6.5, before 6.18.30 (fixed in 6.18.30); from 6.19, before 7.0.7 (fixed in 7.0.7)
Published 2026-05-28. Last modified 2026-06-17.