CVE-2026-31554

Updated on 24 Apr 2026

Severity

8.5 High severity

Details

CVSS score
8.5

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: futex: Require sys_futex_requeue() to have identical flags Nicholas reported that his LLM found it was possible to create a UaF when sys_futex_requeue() is used with different flags. The initial motivation for allowing different flags was the variable sized futex, but since that hasn’t been merged (yet), simply mandate the flags are identical, as is the case for the old style sys_futex() requeue operations. A flaw was found in the Linux kernel. A local attacker could exploit a use-after-free vulnerability by calling the sys_futex_requeue() function with inconsistent flags. This could lead to a system crash, resulting in a denial of service, or potentially allow for privilege escalation.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Planned
Ubuntu 24.04 Planned