CVE-2026-46115
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 platform drivers; - ARM64 architecture; - Cryptographic API; - PSP security protocol; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - User-Mode Linux (UML); - x86 architecture; - Block layer subsystem; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Auxiliary display drivers; - Drivers core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - Ublk userspace block driver; - Compressed RAM block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - Hardware random number generator core; - Clock framework and drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - DPLL subsystem; - EDAC drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - Intel Stratix 10 firmware drivers; - FPGA Framework; - FWCTL subsystem; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - CoreSight HW tracing drivers; - I2C subsystem; - I3C su
CSIRTS triage
- What
- Vulnerabilities in the Linux kernel could allow local attackers to expose sensitive information or escalate privileges.
- Who is affected
- Users of the Linux kernel, especially on affected AMD processors, are impacted.
- Urgency
- Immediate remediation is advised due to the high severity of the vulnerabilities.
- Action
- Upgrade to the latest Linux kernel version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-46115
Get an email if CVE-2026-46115 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Advisory coverage (15)
- unknownexploitedUSN-8728-1: Linux kernel (GCP) vulnerabilitiesubuntu · 2026-09-07
- highUSN-8619-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-28
- highUSN-8609-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8607-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8606-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- unknownUSN-8605-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- unknownUSN-8604-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8603-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8569-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-20
- unknownUSN-8490-2: Linux kernel (Real-time) vulnerabilitiesubuntu · 2026-07-17
- unknownUSN-8490-1: Linux kernel vulnerabilitiesubuntu · 2026-07-17
- unknownUSN-8546-1: Linux kernel (Raspberry Pi) vulnerabilitiesubuntu · 2026-07-15
- unknownUSN-8545-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-15
- unknownUSN-8492-5: Linux kernel (FIPS) vulnerabilitiesubuntu · 2026-07-10
- unknownUSN-8492-4: Linux kernel (Raspberry Pi) vulnerabilitiesubuntu · 2026-07-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-46115)