CVE-2026-31574

Updated on 24 Apr 2026

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

clockevents: Add missing resets of the next_event_forced flag

The prevention mechanism against timer interrupt starvation missed to reset the next_event_forced flag in a couple of places:

  • When the clock event state changes. That can cause the flag to be stale over a shutdown/startup sequence

  • When a non-forced event is armed, which then prevents rearming before that event. If that event is far out in the future this will cause missed timer interrupts.

  • In the suspend wakeup handler.

That led to stalls which have been reported by several people.

Add the missing resets, which fixes the problems for the reporters.

Details

Affected packages:
kernel @ 4.18.0 (+15 more)

In the Linux kernel, the following vulnerability has been resolved:

clockevents: Add missing resets of the next_event_forced flag

The prevention mechanism against timer interrupt starvation missed to reset the next_event_forced flag in a couple of places:

  • When the clock event state changes. That can cause the flag to be stale over a shutdown/startup sequence

  • When a non-forced event is armed, which then prevents rearming before that event. If that event is far out in the future this will cause missed timer interrupts.

  • In the suspend wakeup handler.

That led to stalls which have been reported by several people.

Add the missing resets, which fixes the problems for the reporters.

Fixes