CVE-2026-45476 Details
Description
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
A use-after-free vulnerability has been identified in the Linux MANA driver, allowing an authorized attacker to locally elevate privileges. The vulnerability arises from the driver mishandling memory, which could enable an attacker to access sensitive information from the guest and potentially use it to gain higher privileges within the guest system.
To address this vulnerability, update the Linux kernel to a version that includes the upstream fix, which has been accepted and will be available in future releases. For distributions that have not yet incorporated the update, monitor vendor security advisories and apply the patch when available. Organizations with custom kernels may need to manually backport the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft azure network adapter | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 23, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | [email protected] |