PT-2026-47385 · Linux · Linux Kernel

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-46314

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A local user can cause an infinite loop in the kernel context by crafting a self-referential extension where ext->next == &ext with zero in sync count and out sync count. This occurs because the v3d get extensions() function processes a userspace-provided singly-linked list of ioctl extensions without bounding the chain length. The existing duplicate-extension guard is bypassed because v3d get multisync post deps() returns immediately when the count is zero, leaving both fields at zero during every iteration. This results in the calling thread being blocked and a CPU core being pegged indefinitely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-46314

Affected Products

Linux Kernel