---
cve: "CVE-2026-46268"
severity: "LOW"
cvss: 3.1
epss: "11%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-06-03 18:16:28"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T06:52:01+02:00"
---

# CVE-2026-46268

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition

Commit b7e282378773 has already changed the initial page refcount of
p2pdma page from one to zero, however, in p2pmem_alloc_mmap() it uses
"VM_WARN_ON_ONCE_PAGE(!page_ref_count(page))" to assert the initial page
refcount should not be zero and the following will be reported when
CONFIG_DEBUG_VM is enabled:

  page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x380400000
  flags: 0x20000000002000(reserved|node=0|zone=4)
  raw: 0020000000002000 ff1100015e3ab440 0000000000000000 0000000000000000
  raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
  page dumped because: VM_WARN_ON_ONCE_PAGE(!page_ref_count(page))
  ------------[ cut here ]------------
  WARNING: CPU: 5 PID: 449 at drivers/pci/p2pdma.c:240 p2pmem_alloc_mmap+0x83a/0xa60

Fix by using "page_ref_count(page)" as the assertion condition.

## Patch verfügbar (OSV)

- Kernel ≥ 6.18.14
- Kernel ≥ 6.19.4

## Referenzen

- <https://git.kernel.org/stable/c/eb9aa9f8010465d927864f5a35bdc5604b0ff51a>
- <https://git.kernel.org/stable/c/9b69243983fb2f4d4d1f4ef0989bc1296547dc2c>
- <https://git.kernel.org/stable/c/cb500023a75246f60b79af9f7321d6e75330c5b5>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-46268) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
