In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so calling it before triggers a double free.
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:30848 cve-icon
https://access.redhat.com/errata/RHSA-2026:33685 cve-icon
https://access.redhat.com/errata/RHSA-2026:33743 cve-icon
https://access.redhat.com/errata/RHSA-2026:35904 cve-icon
https://access.redhat.com/errata/RHSA-2026:36049 cve-icon
https://access.redhat.com/errata/RHSA-2026:36073 cve-icon
https://access.redhat.com/errata/RHSA-2026:36767 cve-icon
https://access.redhat.com/errata/RHSA-2026:38902 cve-icon
https://access.redhat.com/errata/RHSA-2026:40068 cve-icon
https://access.redhat.com/errata/RHSA-2026:40760 cve-icon
https://access.redhat.com/errata/RHSA-2026:47633 cve-icon
https://access.redhat.com/security/cve/CVE-2026-46189 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2482588 cve-icon
https://git.kernel.org/stable/c/0c63333ff97bd1275294fd12840a0efe9d7a4c59 cve-icon cve-icon
https://git.kernel.org/stable/c/1df5711121cdc11e76b889408fdbe459feba1d39 cve-icon cve-icon
https://git.kernel.org/stable/c/269967d7693304e1f06ed2dff4ebbbeeb397cda4 cve-icon cve-icon
https://git.kernel.org/stable/c/3a231c34c5bc3d3cfc850b877758ec9fdaa8a483 cve-icon cve-icon
https://git.kernel.org/stable/c/45d25e3ec17900bf5a9d6876ff16ceee31c4c0e0 cve-icon cve-icon
https://git.kernel.org/stable/c/935ee27d0904aa944cbcc979094c20e5ef62eead cve-icon cve-icon
https://git.kernel.org/stable/c/e38e86995df27f1f854063dab1f0c6a513db3faf cve-icon cve-icon
https://git.kernel.org/stable/c/ecc36a82ecfcfdf3c6606d209f22ec5543c410e0 cve-icon cve-icon
https://lore.kernel.org/linux-cve-announce/2026052831-CVE-2026-46189-c188@gregkh/T cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-46189 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46189.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-46189 cve-icon
History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-763

Thu, 11 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
CPEs cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 01 Jun 2026 17:00:00 +0000


Fri, 29 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1341
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 28 May 2026 10:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so calling it before triggers a double free.
Title RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published: 2026-05-28T09:36:43.205Z

Updated: 2026-09-09T12:04:49.181Z

Reserved: 2026-05-13T15:03:33.104Z

Link: CVE-2026-46189

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-05-28T10:16:34.540

Modified: 2026-09-09T13:20:16.377

Link: CVE-2026-46189

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-28T00:00:00Z

Links: CVE-2026-46189 - Bugzilla