CVE-2026-46274 | Linux Kernel up to 7.1-rc3 io-wq io_wq_remove_pending hash_tail[] null pointer dereference

SecurityVulns

A vulnerability was found in Linux Kernel up to 6.6.140/6.12.90/6.18.32/7.0.9/7.1-rc3. It has been classified as critical. This impacts the function io_wq_remove_pending of the component io-wq. Performing a manipulation of the argument hash_tail[] results in null pointer dereference.

This vulnerability was named CVE-2026-46274. The attack needs to be approached within the local network. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More