{"schema_version":"1.7.5","id":"CVE-2026-46173","published":"2026-05-28T09:36:27.892Z","modified":"2026-07-24T18:29:58.150396559Z","related":["ALSA-2026:27288","ALSA-2026:27789","SUSE-SU-2026:22521-1","SUSE-SU-2026:22522-1","SUSE-SU-2026:22598-1","SUSE-SU-2026:22665-1","SUSE-SU-2026:22666-1","SUSE-SU-2026:22672-1","SUSE-SU-2026:22673-1","SUSE-SU-2026:22674-1","SUSE-SU-2026:22675-1","SUSE-SU-2026:22676-1","SUSE-SU-2026:22677-1","SUSE-SU-2026:22678-1","SUSE-SU-2026:22679-1","SUSE-SU-2026:22680-1","SUSE-SU-2026:22681-1","SUSE-SU-2026:22682-1","SUSE-SU-2026:22683-1","SUSE-SU-2026:22684-1","SUSE-SU-2026:22685-1","SUSE-SU-2026:22686-1","SUSE-SU-2026:22687-1","SUSE-SU-2026:22689-1","SUSE-SU-2026:22690-1","SUSE-SU-2026:22691-1","SUSE-SU-2026:22692-1","SUSE-SU-2026:22693-1","SUSE-SU-2026:22694-1","SUSE-SU-2026:22695-1","SUSE-SU-2026:22696-1","SUSE-SU-2026:22697-1","SUSE-SU-2026:22698-1","SUSE-SU-2026:22710-1","SUSE-SU-2026:22711-1","SUSE-SU-2026:22712-1","SUSE-SU-2026:22713-1","SUSE-SU-2026:22714-1","SUSE-SU-2026:22715-1","SUSE-SU-2026:22716-1","SUSE-SU-2026:22717-1","SUSE-SU-2026:22718-1","SUSE-SU-2026:22719-1","SUSE-SU-2026:22720-1","SUSE-SU-2026:22721-1","SUSE-SU-2026:22722-1","SUSE-SU-2026:22723-1","SUSE-SU-2026:22724-1","SUSE-SU-2026:22725-1","SUSE-SU-2026:22726-1","SUSE-SU-2026:22727-1","SUSE-SU-2026:22728-1","SUSE-SU-2026:22729-1","SUSE-SU-2026:22730-1","SUSE-SU-2026:22731-1","SUSE-SU-2026:22732-1","SUSE-SU-2026:22733-1","SUSE-SU-2026:22734-1","SUSE-SU-2026:22735-1","SUSE-SU-2026:22742-1","SUSE-SU-2026:22743-1","SUSE-SU-2026:22744-1","SUSE-SU-2026:22745-1","SUSE-SU-2026:22746-1","SUSE-SU-2026:22747-1","SUSE-SU-2026:22748-1","SUSE-SU-2026:22749-1","SUSE-SU-2026:22751-1","SUSE-SU-2026:22755-1","SUSE-SU-2026:22758-1","SUSE-SU-2026:22759-1","SUSE-SU-2026:22761-1","SUSE-SU-2026:22762-1","SUSE-SU-2026:22763-1","SUSE-SU-2026:22766-1","SUSE-SU-2026:22769-1","SUSE-SU-2026:22773-1","SUSE-SU-2026:22774-1","SUSE-SU-2026:22775-1","SUSE-SU-2026:22776-1","SUSE-SU-2026:22777-1","SUSE-SU-2026:22778-1","SUSE-SU-2026:22779-1","SUSE-SU-2026:22780-1","SUSE-SU-2026:22781-1","SUSE-SU-2026:22782-1","SUSE-SU-2026:22783-1","SUSE-SU-2026:22784-1","SUSE-SU-2026:22785-1","SUSE-SU-2026:22786-1","SUSE-SU-2026:2799-1","SUSE-SU-2026:2800-1","SUSE-SU-2026:2840-1","SUSE-SU-2026:2841-1","SUSE-SU-2026:2855-1","SUSE-SU-2026:2857-1","SUSE-SU-2026:2858-1","SUSE-SU-2026:2862-1","SUSE-SU-2026:2863-1","SUSE-SU-2026:2864-1","SUSE-SU-2026:2866-1","SUSE-SU-2026:2867-1","SUSE-SU-2026:2868-1","SUSE-SU-2026:2887-1","SUSE-SU-2026:2888-1","SUSE-SU-2026:2889-1","SUSE-SU-2026:2890-1","SUSE-SU-2026:2894-1","SUSE-SU-2026:2895-1","SUSE-SU-2026:2899-1","SUSE-SU-2026:2902-1","SUSE-SU-2026:2910-1","SUSE-SU-2026:2920-1","SUSE-SU-2026:2930-1","SUSE-SU-2026:2932-1","SUSE-SU-2026:2933-1","SUSE-SU-2026:2937-1","SUSE-SU-2026:2938-1","SUSE-SU-2026:2943-1","SUSE-SU-2026:2945-1","SUSE-SU-2026:2956-1","SUSE-SU-2026:2957-1","SUSE-SU-2026:2961-1","SUSE-SU-2026:2989-1","SUSE-SU-2026:2991-1","SUSE-SU-2026:2993-1","SUSE-SU-2026:2997-1","SUSE-SU-2026:3001-1","SUSE-SU-2026:3002-1","SUSE-SU-2026:3008-1","SUSE-SU-2026:3009-1","SUSE-SU-2026:3044-1","SUSE-SU-2026:3075-1","SUSE-SU-2026:3083-1","SUSE-SU-2026:3089-1","SUSE-SU-2026:3156-1","openSUSE-SU-2026:10954-1","openSUSE-SU-2026:21388-1"],"summary":"exit: prevent preemption of oopsing TASK_DEAD task","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nexit: prevent preemption of oopsing TASK_DEAD task\n\nWhen an already-exiting task oopses, make_task_dead() currently calls\ndo_task_dead() with preemption enabled.  That is forbidden:\ndo_task_dead() calls __schedule(), which has a comment saying \"WARNING:\nmust be called with preemption disabled!\".\n\nIf an oopsing task is preempted in do_task_dead(), between becoming\nTASK_DEAD and entering the scheduler explicitly, bad things happen:\nfinish_task_switch() assumes that once the scheduler has switched away\nfrom a TASK_DEAD task, the task can never run again and its stack is no\nlonger needed; but that assumption apparently doesn't hold if the dead\ntask was preempted (the SM_PREEMPT case).\n\nThis means that the scheduler ends up repeatedly dropping references on\nthe dead task's stack, which can lead to use-after-free or double-free\nof the entire task stack; in other words, two tasks can end up running\non the same stack, resulting in various kinds of memory corruption.\n\n(This does not just affect \"recursively oopsing\" tasks; it is enough to\noops once during task exit, for example in a file_operations::release\nhandler)","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"7f80a2fd7db9a55894fd841915236aca611291b5"},{"fixed":"3d6fb8a7690c23e3213c4b008f64d89a44b98737"},{"fixed":"640b4c00fb0e2920327435f6176cbefc3c546165"},{"fixed":"7b2800ba5f5f77a8ee7f4cbadb19cf1264597a34"},{"fixed":"6f49f94f3b11fe8bff1bf2a054143789e76aaf17"},{"fixed":"9756b3db5db6c2f5eccb32dddbd88eb4c54f575e"},{"fixed":"c1fa0bb633e4a6b11e83ffc57fa5abe8ebb87891"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46173.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.17.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.140"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.88"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.30"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46173.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3d6fb8a7690c23e3213c4b008f64d89a44b98737"},{"type":"WEB","url":"https://git.kernel.org/stable/c/640b4c00fb0e2920327435f6176cbefc3c546165"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6f49f94f3b11fe8bff1bf2a054143789e76aaf17"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7b2800ba5f5f77a8ee7f4cbadb19cf1264597a34"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9756b3db5db6c2f5eccb32dddbd88eb4c54f575e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c1fa0bb633e4a6b11e83ffc57fa5abe8ebb87891"},{"type":"WEB","url":"https://project-zero.issues.chromium.org/issues/510793286"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46173.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46173"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46173.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}