HOMEVULNERABILITIESCVE-2026-46250
HIGH

CVE-2026-46250

Published: June 3, 2026· Updated: Jun 9, 2026

7.3
CVSS v3.1
EPSS:0.02%probability of exploitation in 30 daysPercentile:7.2th

Official Description

In the Linux kernel, the following vulnerability has been resolved:

MIPS: Work around LLVM bug when gp is used as global register variable

On MIPS, __current_thread_info is defined as global register variable

locating in $gp, and is simply assigned with new address during kernel

relocation.

This however is broken with LLVM, which always restores $gp if it finds

$gp is clobbered in any form, including when intentionally through a

global register variable. This is against GCC's documentation[1], which

requires a callee-saved register used as global register variable not to

be restored if it's clobbered.

As a result, $gp will continue to point to the unrelocated kernel after

the epilog of relocate_kernel(), leading to an early crash in init_idle,

[ 0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000000000000000, epc == ffffffff81afada8, ra == ffffffff81afad90

[ 0.000000] Oops[#1]:

[ 0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper Tainted: G W 6.19.0-rc5-00262-gd3eeb99bbc99-dirty #188 VOLUNTARY

[ 0.000000] Tainted: [W]=WARN

[ 0.000000] Hardware name: loongson,loongson64v-4core-virtio

[ 0.000000] $ 0 : 0000000000000000 0000000000000000 0000000000000001 0000000000000000

[ 0.000000] $ 4 : ffffffff80b80ec0 ffffffff80b53d48 0000000000000000 00000000000f4240

[ 0.000000] $ 8 : 0000000000000100 ffffffff81d82f80 ffffffff81d82f80 0000000000000001

[ 0.000000] $12 : 0000000000000000 ffffffff81776f58 00000000000005da 0000000000000002

[ 0.000000] $16 : ffffffff80b80e40 0000000000000000 ffffffff80b81614 9800000005dfbe80

[ 0.000000] $20 : 00000000540000e0 ffffffff81980000 0000000000000000 ffffffff80f81c80

[ 0.000000] $24 : 0000000000000a26 ffffffff8114fb90

[ 0.000000] $28 : ffffffff80b50000 ffffffff80b53d40 0000000000000000 ffffffff81afad90

[ 0.000000] Hi : 0000000000000000

[ 0.000000] Lo : 0000000000000000

[ 0.000000] epc : ffffffff81afada8 init_idle+0x130/0x270

[ 0.000000] ra : ffffffff81afad90 init_idle+0x118/0x270

[ 0.000000] Status: 540000e2 KX SX UX KERNEL EXL

[ 0.000000] Cause : 00000008 (ExcCode 02)

[ 0.000000] BadVA : 0000000000000000

[ 0.000000] PrId : 00006305 (ICT Loongson-3)

[ 0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)

[ 0.000000] Stack : 9800000005dfbf00 ffffffff8178e950 0000000000000000 0000000000000000

[ 0.000000] 0000000000000000 ffffffff81970000 000000000000003f ffffffff810a6528

[ 0.000000] 0000000000000001 9800000005dfbe80 9800000005dfbf00 ffffffff81980000

[ 0.000000] ffffffff810a6450 ffffffff81afb6c0 0000000000000000 ffffffff810a2258

[ 0.000000] ffffffff81d82ec8 ffffffff8198d010 ffffffff81b67e80 ffffffff8197dd98

[ 0.000000] ffffffff81d81c80 ffffffff81930000 0000000000000040 0000000000000000

[ 0.000000] 0000000000000000 0000000000000000 0000000000000000 0000000000000000

[ 0.000000] 0000000000000000 000000000000009e ffffffff9fc01000 0000000000000000

[ 0.000000] 0000000000000000 0000000000000000 0000000000000000 0000000000000000

[ 0.000000] 0000000000000000 ffffffff81ae86dc ffffffff81b3c741 0000000000000002

[ 0.000000] ...

[ 0.000000] Call Trace:

[ 0.000000] [<ffffffff81afada8>] init_idle+0x130/0x270

[ 0.000000] [<ffffffff81afb6c0>] sched_init+0x5c8/0x6c0

[ 0.000000] [<ffffffff81ae86dc>] start_kernel+0x27c/0x7a8

This bug has been reported to LLVM[2] and affects version from (at

least) 18 to 21. Let's work around this by using inline assembly to

assign $gp before a fix is widely available.

NVD Source

Technical Analysis

CVE-2026-46250 requires local access, meaning attackers must already have a foothold on the target system.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in availability disruption (denial of service), with a CVSS base score of 7.3.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityLow
IntegrityLow
AvailabilityHigh
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected Vendors & Products

Linux1 product(s)
linux kernel
Source: NVD CPE · 1 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (8)

Quick Facts

CVE IDCVE-2026-46250
CVSS Score7.3 / 10
SeverityHIGH
CISA KEVNo
EPSS (30d)0.02%
Affected1 vendor(s)
PublishedJun 3, 2026

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-46250 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.