Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-348052
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 08:17
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T08:17:06.168746+00:00",
"id": "EUVD-2026-348052"
}
CVE-2026-46250 (GCVE-0-2026-46250)
Vulnerability from cvelistv5 – Published: 2026-06-03 15:49 – Updated: 2026-08-05 12:30
VLAI
EPSS
VEX
Title
MIPS: Work around LLVM bug when gp is used as global register variable
Summary
In the Linux kernel, the following vulnerability has been resolved:
MIPS: Work around LLVM bug when gp is used as global register variable
On MIPS, __current_thread_info is defined as global register variable
locating in $gp, and is simply assigned with new address during kernel
relocation.
This however is broken with LLVM, which always restores $gp if it finds
$gp is clobbered in any form, including when intentionally through a
global register variable. This is against GCC's documentation[1], which
requires a callee-saved register used as global register variable not to
be restored if it's clobbered.
As a result, $gp will continue to point to the unrelocated kernel after
the epilog of relocate_kernel(), leading to an early crash in init_idle,
[ 0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000000000000000, epc == ffffffff81afada8, ra == ffffffff81afad90
[ 0.000000] Oops[#1]:
[ 0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper Tainted: G W 6.19.0-rc5-00262-gd3eeb99bbc99-dirty #188 VOLUNTARY
[ 0.000000] Tainted: [W]=WARN
[ 0.000000] Hardware name: loongson,loongson64v-4core-virtio
[ 0.000000] $ 0 : 0000000000000000 0000000000000000 0000000000000001 0000000000000000
[ 0.000000] $ 4 : ffffffff80b80ec0 ffffffff80b53d48 0000000000000000 00000000000f4240
[ 0.000000] $ 8 : 0000000000000100 ffffffff81d82f80 ffffffff81d82f80 0000000000000001
[ 0.000000] $12 : 0000000000000000 ffffffff81776f58 00000000000005da 0000000000000002
[ 0.000000] $16 : ffffffff80b80e40 0000000000000000 ffffffff80b81614 9800000005dfbe80
[ 0.000000] $20 : 00000000540000e0 ffffffff81980000 0000000000000000 ffffffff80f81c80
[ 0.000000] $24 : 0000000000000a26 ffffffff8114fb90
[ 0.000000] $28 : ffffffff80b50000 ffffffff80b53d40 0000000000000000 ffffffff81afad90
[ 0.000000] Hi : 0000000000000000
[ 0.000000] Lo : 0000000000000000
[ 0.000000] epc : ffffffff81afada8 init_idle+0x130/0x270
[ 0.000000] ra : ffffffff81afad90 init_idle+0x118/0x270
[ 0.000000] Status: 540000e2 KX SX UX KERNEL EXL
[ 0.000000] Cause : 00000008 (ExcCode 02)
[ 0.000000] BadVA : 0000000000000000
[ 0.000000] PrId : 00006305 (ICT Loongson-3)
[ 0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)
[ 0.000000] Stack : 9800000005dfbf00 ffffffff8178e950 0000000000000000 0000000000000000
[ 0.000000] 0000000000000000 ffffffff81970000 000000000000003f ffffffff810a6528
[ 0.000000] 0000000000000001 9800000005dfbe80 9800000005dfbf00 ffffffff81980000
[ 0.000000] ffffffff810a6450 ffffffff81afb6c0 0000000000000000 ffffffff810a2258
[ 0.000000] ffffffff81d82ec8 ffffffff8198d010 ffffffff81b67e80 ffffffff8197dd98
[ 0.000000] ffffffff81d81c80 ffffffff81930000 0000000000000040 0000000000000000
[ 0.000000] 0000000000000000 0000000000000000 0000000000000000 0000000000000000
[ 0.000000] 0000000000000000 000000000000009e ffffffff9fc01000 0000000000000000
[ 0.000000] 0000000000000000 0000000000000000 0000000000000000 0000000000000000
[ 0.000000] 0000000000000000 ffffffff81ae86dc ffffffff81b3c741 0000000000000002
[ 0.000000] ...
[ 0.000000] Call Trace:
[ 0.000000] [<ffffffff81afada8>] init_idle+0x130/0x270
[ 0.000000] [<ffffffff81afb6c0>] sched_init+0x5c8/0x6c0
[ 0.000000] [<ffffffff81ae86dc>] start_kernel+0x27c/0x7a8
This bug has been reported to LLVM[2] and affects version from (at
least) 18 to 21. Let's work around this by using inline assembly to
assign $gp before a fix is widely available.
Severity
7.3 (High)
Assigner
References
8 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
279b991b24d2439fbe9d2f093988b9c8aed2603d , < 05bff9b0ae095b2420cfebb4a96759a09334bec6
(git)
Affected: 279b991b24d2439fbe9d2f093988b9c8aed2603d , < 1fe3b402b1e97a1718df3be0a1d3eee20133e735 (git) Affected: 279b991b24d2439fbe9d2f093988b9c8aed2603d , < 4dc65b40fb80c2020efbf139b9a38d30f9a37b92 (git) Affected: 279b991b24d2439fbe9d2f093988b9c8aed2603d , < c0155dee51b9f5f48aaf5c71cae005eb0e36521f (git) Affected: 279b991b24d2439fbe9d2f093988b9c8aed2603d , < e3a6498a63394218561065a9a7a597a204f52f6a (git) Affected: 279b991b24d2439fbe9d2f093988b9c8aed2603d , < 561834f6d6f52b8a1791331e94b2aac753491d2a (git) Affected: 279b991b24d2439fbe9d2f093988b9c8aed2603d , < 9bc3b0ae5203aba650297fdf3e1e774125e423f2 (git) Affected: 279b991b24d2439fbe9d2f093988b9c8aed2603d , < 30bfc2d6a1132a89a5f1c3b96c59cf3e4d076ea3 (git) |
|
| Linux | Linux |
Affected:
4.7
Unaffected: 0 , < 4.7 (semver) Unaffected: 5.10.252 , ≤ 5.10.* (semver) Unaffected: 5.15.202 , ≤ 5.15.* (semver) Unaffected: 6.1.165 , ≤ 6.1.* (semver) Unaffected: 6.6.128 , ≤ 6.6.* (semver) Unaffected: 6.12.75 , ≤ 6.12.* (semver) Unaffected: 6.18.14 , ≤ 6.18.* (semver) Unaffected: 6.19.4 , ≤ 6.19.* (semver) Unaffected: 7.0 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/mips/kernel/relocate.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "05bff9b0ae095b2420cfebb4a96759a09334bec6",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
},
{
"lessThan": "1fe3b402b1e97a1718df3be0a1d3eee20133e735",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
},
{
"lessThan": "4dc65b40fb80c2020efbf139b9a38d30f9a37b92",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
},
{
"lessThan": "c0155dee51b9f5f48aaf5c71cae005eb0e36521f",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
},
{
"lessThan": "e3a6498a63394218561065a9a7a597a204f52f6a",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
},
{
"lessThan": "561834f6d6f52b8a1791331e94b2aac753491d2a",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
},
{
"lessThan": "9bc3b0ae5203aba650297fdf3e1e774125e423f2",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
},
{
"lessThan": "30bfc2d6a1132a89a5f1c3b96c59cf3e4d076ea3",
"status": "affected",
"version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/mips/kernel/relocate.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: Work around LLVM bug when gp is used as global register variable\n\nOn MIPS, __current_thread_info is defined as global register variable\nlocating in $gp, and is simply assigned with new address during kernel\nrelocation.\n\nThis however is broken with LLVM, which always restores $gp if it finds\n$gp is clobbered in any form, including when intentionally through a\nglobal register variable. This is against GCC\u0027s documentation[1], which\nrequires a callee-saved register used as global register variable not to\nbe restored if it\u0027s clobbered.\n\nAs a result, $gp will continue to point to the unrelocated kernel after\nthe epilog of relocate_kernel(), leading to an early crash in init_idle,\n\n[ 0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000000000000000, epc == ffffffff81afada8, ra == ffffffff81afad90\n[ 0.000000] Oops[#1]:\n[ 0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper Tainted: G W 6.19.0-rc5-00262-gd3eeb99bbc99-dirty #188 VOLUNTARY\n[ 0.000000] Tainted: [W]=WARN\n[ 0.000000] Hardware name: loongson,loongson64v-4core-virtio\n[ 0.000000] $ 0 : 0000000000000000 0000000000000000 0000000000000001 0000000000000000\n[ 0.000000] $ 4 : ffffffff80b80ec0 ffffffff80b53d48 0000000000000000 00000000000f4240\n[ 0.000000] $ 8 : 0000000000000100 ffffffff81d82f80 ffffffff81d82f80 0000000000000001\n[ 0.000000] $12 : 0000000000000000 ffffffff81776f58 00000000000005da 0000000000000002\n[ 0.000000] $16 : ffffffff80b80e40 0000000000000000 ffffffff80b81614 9800000005dfbe80\n[ 0.000000] $20 : 00000000540000e0 ffffffff81980000 0000000000000000 ffffffff80f81c80\n[ 0.000000] $24 : 0000000000000a26 ffffffff8114fb90\n[ 0.000000] $28 : ffffffff80b50000 ffffffff80b53d40 0000000000000000 ffffffff81afad90\n[ 0.000000] Hi : 0000000000000000\n[ 0.000000] Lo : 0000000000000000\n[ 0.000000] epc : ffffffff81afada8 init_idle+0x130/0x270\n[ 0.000000] ra : ffffffff81afad90 init_idle+0x118/0x270\n[ 0.000000] Status: 540000e2\tKX SX UX KERNEL EXL\n[ 0.000000] Cause : 00000008 (ExcCode 02)\n[ 0.000000] BadVA : 0000000000000000\n[ 0.000000] PrId : 00006305 (ICT Loongson-3)\n[ 0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)\n[ 0.000000] Stack : 9800000005dfbf00 ffffffff8178e950 0000000000000000 0000000000000000\n[ 0.000000] 0000000000000000 ffffffff81970000 000000000000003f ffffffff810a6528\n[ 0.000000] 0000000000000001 9800000005dfbe80 9800000005dfbf00 ffffffff81980000\n[ 0.000000] ffffffff810a6450 ffffffff81afb6c0 0000000000000000 ffffffff810a2258\n[ 0.000000] ffffffff81d82ec8 ffffffff8198d010 ffffffff81b67e80 ffffffff8197dd98\n[ 0.000000] ffffffff81d81c80 ffffffff81930000 0000000000000040 0000000000000000\n[ 0.000000] 0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[ 0.000000] 0000000000000000 000000000000009e ffffffff9fc01000 0000000000000000\n[ 0.000000] 0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[ 0.000000] 0000000000000000 ffffffff81ae86dc ffffffff81b3c741 0000000000000002\n[ 0.000000] ...\n[ 0.000000] Call Trace:\n[ 0.000000] [\u003cffffffff81afada8\u003e] init_idle+0x130/0x270\n[ 0.000000] [\u003cffffffff81afb6c0\u003e] sched_init+0x5c8/0x6c0\n[ 0.000000] [\u003cffffffff81ae86dc\u003e] start_kernel+0x27c/0x7a8\n\nThis bug has been reported to LLVM[2] and affects version from (at\nleast) 18 to 21. Let\u0027s work around this by using inline assembly to\nassign $gp before a fix is widely available."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code runs only during early boot in `relocate_kernel()` (`arch/mips/kernel/head.S` \u2192 `arch/mips/kernel/relocate.c`), before any network stack or syscall interface exists; the only way to reach it is to boot or reboot the MIPS system locally.\nAC:L - When the kernel is built with LLVM/Clang, `CONFIG_RELOCATABLE`, and KASLR relocation (`offset != 0`), LLVM deterministically restores `$gp` in the `relocate_kernel()` epilog, causing a reliable crash in `init_idle()` on every affected boot without races or attacker-uncontrollable timing.\nPR:N - Execution occurs in the pre-authentication boot path (PID 0 swapper during `start_kernel()` \u2192 `sched_init()` \u2192 `init_idle()`), before any user login or privilege checks; no attacker credentials are required at the time the bug triggers.\nUI:N - No victim user action is required beyond normal system power-on or reboot; the fault occurs automatically during kernel initialization on affected builds.\nS:U - Impact is confined to kernel boot failure on the same machine; there is no crossing of security boundaries such as VM escape, sandbox escape, or IOMMU bypass.\nC:L - The stale `$gp`/`__current_thread_info` causes `current` to resolve from the unrelocated `init_thread_union`, leading to dereferences of invalid kernel memory and limited kernel-address information exposure in the oops before the paging fault at address 0.\nI:L - Before the fatal fault, `init_idle()` performs writes through the mis-resolved `current` pointer (e.g., task state and scheduler fields), enabling limited unintended modification of kernel structures even though the immediate outcome is a crash rather than controlled code execution.\nA:H - The bug produces a kernel oops during early boot in `init_idle()` with \"Unable to handle kernel paging request at virtual address 0000000000000000\", preventing the system from completing initialization and rendering it unavailable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:30:44.867Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/05bff9b0ae095b2420cfebb4a96759a09334bec6"
},
{
"url": "https://git.kernel.org/stable/c/1fe3b402b1e97a1718df3be0a1d3eee20133e735"
},
{
"url": "https://git.kernel.org/stable/c/4dc65b40fb80c2020efbf139b9a38d30f9a37b92"
},
{
"url": "https://git.kernel.org/stable/c/c0155dee51b9f5f48aaf5c71cae005eb0e36521f"
},
{
"url": "https://git.kernel.org/stable/c/e3a6498a63394218561065a9a7a597a204f52f6a"
},
{
"url": "https://git.kernel.org/stable/c/561834f6d6f52b8a1791331e94b2aac753491d2a"
},
{
"url": "https://git.kernel.org/stable/c/9bc3b0ae5203aba650297fdf3e1e774125e423f2"
},
{
"url": "https://git.kernel.org/stable/c/30bfc2d6a1132a89a5f1c3b96c59cf3e4d076ea3"
}
],
"title": "MIPS: Work around LLVM bug when gp is used as global register variable",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46250",
"datePublished": "2026-06-03T15:49:46.390Z",
"dateReserved": "2026-05-13T15:03:33.107Z",
"dateUpdated": "2026-08-05T12:30:44.867Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…