CVE-2026-46173 is a Linux kernel vulnerability in task exit handling. When an already-exiting task triggers an oops, make_task_dead() can call do_task_dead() with preemption enabled, even though do_task_dead() ultimately reaches __schedule(), which must be entered with preemption disabled. If the oopsing task is preempted after it has become TASK_DEAD but before it explicitly enters the scheduler, scheduler invariants are broken: finish_task_switch() assumes a TASK_DEAD task that has been switched away from will never run again and that its stack is no longer needed. In the preempted case, that assumption fails, causing repeated dropping of references to the dead task's stack and leading to use-after-free or double-free of the task stack. This can result in two tasks running on the same stack and broader kernel memory corruption. The issue can be triggered by a single oops during task exit, including in paths such as a file_operations::release handler.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.