CVE-2026-31436

Updated on 22 Apr 2026

Severity

9.8 Critical severity

Details

CVSS score
9.8

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() At the end of this function, d is the traversal cursor of flist, but the code completes found instead. This can lead to issues such as NULL pointer dereferences, double completion, or descriptor leaks. Fix this by completing d instead of found in the final list_for_each_entry_safe() loop. A flaw was found in the Linux kernel’s dmaengine subsystem, specifically within the idxd driver. This vulnerability occurs due to incorrect descriptor completion in the llist_abort_desc() function. This can lead to issues such as NULL pointer dereferences, double completion, or descriptor leaks, which can result in a denial of service.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Planned
Ubuntu 24.04 Planned
Ubuntu 24.04 AWS Planned