{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-46250",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-05-13T15:03:33.107Z",
        "datePublished": "2026-06-03T15:49:46.390Z",
        "dateUpdated": "2026-08-05T12:30:44.867Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:30:44.867Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: Work around LLVM bug when gp is used as global register variable\n\nOn MIPS, __current_thread_info is defined as global register variable\nlocating in $gp, and is simply assigned with new address during kernel\nrelocation.\n\nThis however is broken with LLVM, which always restores $gp if it finds\n$gp is clobbered in any form, including when intentionally through a\nglobal register variable. This is against GCC's documentation[1], which\nrequires a callee-saved register used as global register variable not to\nbe restored if it's clobbered.\n\nAs a result, $gp will continue to point to the unrelocated kernel after\nthe epilog of relocate_kernel(), leading to an early crash in init_idle,\n\n[    0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000000000000000, epc == ffffffff81afada8, ra == ffffffff81afad90\n[    0.000000] Oops[#1]:\n[    0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper Tainted: G        W           6.19.0-rc5-00262-gd3eeb99bbc99-dirty #188 VOLUNTARY\n[    0.000000] Tainted: [W]=WARN\n[    0.000000] Hardware name: loongson,loongson64v-4core-virtio\n[    0.000000] $ 0   : 0000000000000000 0000000000000000 0000000000000001 0000000000000000\n[    0.000000] $ 4   : ffffffff80b80ec0 ffffffff80b53d48 0000000000000000 00000000000f4240\n[    0.000000] $ 8   : 0000000000000100 ffffffff81d82f80 ffffffff81d82f80 0000000000000001\n[    0.000000] $12   : 0000000000000000 ffffffff81776f58 00000000000005da 0000000000000002\n[    0.000000] $16   : ffffffff80b80e40 0000000000000000 ffffffff80b81614 9800000005dfbe80\n[    0.000000] $20   : 00000000540000e0 ffffffff81980000 0000000000000000 ffffffff80f81c80\n[    0.000000] $24   : 0000000000000a26 ffffffff8114fb90\n[    0.000000] $28   : ffffffff80b50000 ffffffff80b53d40 0000000000000000 ffffffff81afad90\n[    0.000000] Hi    : 0000000000000000\n[    0.000000] Lo    : 0000000000000000\n[    0.000000] epc   : ffffffff81afada8 init_idle+0x130/0x270\n[    0.000000] ra    : ffffffff81afad90 init_idle+0x118/0x270\n[    0.000000] Status: 540000e2\tKX SX UX KERNEL EXL\n[    0.000000] Cause : 00000008 (ExcCode 02)\n[    0.000000] BadVA : 0000000000000000\n[    0.000000] PrId  : 00006305 (ICT Loongson-3)\n[    0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)\n[    0.000000] Stack : 9800000005dfbf00 ffffffff8178e950 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 ffffffff81970000 000000000000003f ffffffff810a6528\n[    0.000000]         0000000000000001 9800000005dfbe80 9800000005dfbf00 ffffffff81980000\n[    0.000000]         ffffffff810a6450 ffffffff81afb6c0 0000000000000000 ffffffff810a2258\n[    0.000000]         ffffffff81d82ec8 ffffffff8198d010 ffffffff81b67e80 ffffffff8197dd98\n[    0.000000]         ffffffff81d81c80 ffffffff81930000 0000000000000040 0000000000000000\n[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 000000000000009e ffffffff9fc01000 0000000000000000\n[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 ffffffff81ae86dc ffffffff81b3c741 0000000000000002\n[    0.000000]         ...\n[    0.000000] Call Trace:\n[    0.000000] [<ffffffff81afada8>] init_idle+0x130/0x270\n[    0.000000] [<ffffffff81afb6c0>] sched_init+0x5c8/0x6c0\n[    0.000000] [<ffffffff81ae86dc>] start_kernel+0x27c/0x7a8\n\nThis bug has been reported to LLVM[2] and affects version from (at\nleast) 18 to 21. Let's work around this by using inline assembly to\nassign $gp before a fix is widely available."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code runs only during early boot in `relocate_kernel()` (`arch/mips/kernel/head.S` → `arch/mips/kernel/relocate.c`), before any network stack or syscall interface exists; the only way to reach it is to boot or reboot the MIPS system locally.\nAC:L - When the kernel is built with LLVM/Clang, `CONFIG_RELOCATABLE`, and KASLR relocation (`offset != 0`), LLVM deterministically restores `$gp` in the `relocate_kernel()` epilog, causing a reliable crash in `init_idle()` on every affected boot without races or attacker-uncontrollable timing.\nPR:N - Execution occurs in the pre-authentication boot path (PID 0 swapper during `start_kernel()` → `sched_init()` → `init_idle()`), before any user login or privilege checks; no attacker credentials are required at the time the bug triggers.\nUI:N - No victim user action is required beyond normal system power-on or reboot; the fault occurs automatically during kernel initialization on affected builds.\nS:U - Impact is confined to kernel boot failure on the same machine; there is no crossing of security boundaries such as VM escape, sandbox escape, or IOMMU bypass.\nC:L - The stale `$gp`/`__current_thread_info` causes `current` to resolve from the unrelocated `init_thread_union`, leading to dereferences of invalid kernel memory and limited kernel-address information exposure in the oops before the paging fault at address 0.\nI:L - Before the fatal fault, `init_idle()` performs writes through the mis-resolved `current` pointer (e.g., task state and scheduler fields), enabling limited unintended modification of kernel structures even though the immediate outcome is a crash rather than controlled code execution.\nA:H - The bug produces a kernel oops during early boot in `init_idle()` with \"Unable to handle kernel paging request at virtual address 0000000000000000\", preventing the system from completing initialization and rendering it unavailable."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "arch/mips/kernel/relocate.c"
                    ],
                    "versions": [
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "05bff9b0ae095b2420cfebb4a96759a09334bec6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "1fe3b402b1e97a1718df3be0a1d3eee20133e735",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "4dc65b40fb80c2020efbf139b9a38d30f9a37b92",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "c0155dee51b9f5f48aaf5c71cae005eb0e36521f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "e3a6498a63394218561065a9a7a597a204f52f6a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "561834f6d6f52b8a1791331e94b2aac753491d2a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "9bc3b0ae5203aba650297fdf3e1e774125e423f2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
                            "lessThan": "30bfc2d6a1132a89a5f1c3b96c59cf3e4d076ea3",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "arch/mips/kernel/relocate.c"
                    ],
                    "versions": [
                        {
                            "version": "4.7",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.7",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.252",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.202",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.165",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.128",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.75",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.14",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.19.4",
                            "lessThanOrEqual": "6.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "5.10.252"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "5.15.202"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "6.1.165"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "6.6.128"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "6.12.75"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "6.18.14"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "6.19.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.7",
                                    "versionEndExcluding": "7.0"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/05bff9b0ae095b2420cfebb4a96759a09334bec6"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1fe3b402b1e97a1718df3be0a1d3eee20133e735"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4dc65b40fb80c2020efbf139b9a38d30f9a37b92"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c0155dee51b9f5f48aaf5c71cae005eb0e36521f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/e3a6498a63394218561065a9a7a597a204f52f6a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/561834f6d6f52b8a1791331e94b2aac753491d2a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9bc3b0ae5203aba650297fdf3e1e774125e423f2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/30bfc2d6a1132a89a5f1c3b96c59cf3e4d076ea3"
                }
            ],
            "title": "MIPS: Work around LLVM bug when gp is used as global register variable",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}