CVE-2026-46147 | Linux Kernel up to 6.18.29/7.0.6/7.1-rc1 KVM __pkvm_init_vcpu vcpus[] locking
A vulnerability was found in Linux Kernel up to 6.18.29/7.0.6/7.1-rc1. It has been declared as critical. The affected element is the function __pkvm_init_vcpu of the component KVM. Such manipulation of the argument vcpus[] leads to improper locking.
This vulnerability is referenced as CVE-2026-46147. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.