CVE-2026-46187 Details
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: fix kthread lifetime race between self-exit and external-stop RSI driver use both self-exit(kthread_complete_and_exit) and external-stop (kthread_stop) when killing a kthread. Generally, kthread_stop() is called first, and in this case, no particular issues occur. However, in rare instances where kthread_complete_and_exit() is called first and then kthread_stop() is called, a UAF occurs because the kthread object, which has already exited and been freed, is accessed again. Therefore, to prevent this with minimal modification, you must remove kthread_stop() and change the code to wait until the self-exit operation is completed.
A use-after-free vulnerability has been identified in the Linux kernel's WiFi RSI driver, specifically in the handling of kernel threads. This issue arises from a race condition between the self-exit and external-stop processes when terminating a kernel thread. Normally, the external-stop function is called first without any problems. However, in rare cases where the self-exit function is invoked first, followed by the external-stop, the kthread object is accessed after it has already been freed, leading to a use-after-free scenario.
The vulnerability has been addressed by modifying the RSI driver's thread termination process. The external-stop function 'kthread_stop' has been removed, and the code now waits for the self-exit operation to complete before proceeding. Users should apply the latest patches available in the Linux kernel stable tree to mitigate this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/16d9f674c619838bdeae42abc0929c9c5477ea1f | kernel.org | Patch |
| https://git.kernel.org/stable/c/4ac3095da22fc50e51ec10c3b8323c21ab3e441a | kernel.org | Patch |
| https://git.kernel.org/stable/c/4f4c9b13c485abd0a2d2c97f9db339d1dd8e147f | kernel.org | Patch |
| https://git.kernel.org/stable/c/4f697813162d5f9151726a6d2bee82bffe4b0256 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4f9a4ae8d2c198f01611ea376034c326ef43ab56 | kernel.org | Patch |
| https://git.kernel.org/stable/c/95fcb436586dc3c2983537d557ac05bbc6a027f3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9dfe8a4458a063c6433526bc59112a169eee1aa3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/db57a1aa54ff68669781976e4edb045e09e2b65b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.18.139, < 3.19 >= 4.4.179, < 4.5 >= 4.9.170, < 4.10 >= 4.14.113, < 4.15 >= 4.19.36, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.88 >= 6.13, < 6.18.30 >= 6.19, < 7.0.7 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 11, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |