CVE-2026-46011 Details
Description
In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: fix use-after-free in release path due to uncancelled work The mtk_jpeg_release() function frees the context structure (ctx) without first cancelling any pending or running work in ctx->jpeg_work. This creates a race window where the workqueue callback may still be accessing the context memory after it has been freed. Race condition: CPU 0 (release) CPU 1 (workqueue) ---------------- ------------------ close() mtk_jpeg_release() mtk_jpegenc_worker() ctx = work->data // accessing ctx kfree(ctx) // freed! access ctx // UAF! The work is queued via queue_work() during JPEG encode/decode operations (via mtk_jpeg_device_run). If the device is closed while work is pending or running, the work handler will access freed memory. Fix this by calling cancel_work_sync() BEFORE acquiring the mutex. This ordering is critical: if cancel_work_sync() is called after mutex_lock(), and the work handler also tries to acquire the same mutex, it would cause a deadlock. Note: The open error path does NOT need cancel_work_sync() because INIT_WORK() only initializes the work structure - it does not schedule it. Work is only scheduled later during ioctl operations.
A use-after-free vulnerability has been identified in the Linux kernel's media framework, specifically within the MTK JPEG encoding component. This issue arises in the 'mtk_jpeg_release()' function, which frees the context structure without first canceling any pending or running work. As a result, a race condition is created, allowing the workqueue callback to access freed memory, leading to a use-after-free scenario. The vulnerability is present in the Linux kernel stable tree.
The vulnerability has been fixed by modifying the 'mtk_jpeg_release()' function to call 'cancel_work_sync()' before acquiring the mutex, ensuring that any pending work is properly canceled before the context is freed. Users should upgrade to the latest version of the Linux kernel stable tree where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0498b27a1542021d90269d58347501d4c3ccd84e | kernel.org | Patch |
| https://git.kernel.org/stable/c/2209fdae5c2f615930c9af1379c1cfca199ec5d8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/26506a30e0e26d612f82a7bf0e395626968a44e6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/34c519feef3e4fcff1078dc8bdb25fbbbd10303f | kernel.org | Patch |
| https://git.kernel.org/stable/c/e78c39f720679fcf3a2eacd82725ec3ea2648301 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.2, < 6.6.140 >= 6.7, < 6.12.86 >= 6.13, < 6.18.27 >= 6.19, < 7.0.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| May 30, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |