CVE Database
/

CVE-2026-31442

Back to search

CVE-2026-31442

Published: Apr 22, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible invalid memory access after FLR In the case that the first Function Level Reset (FLR) concludes correctly, but in the second FLR the scratch area for the saved configuration cannot be allocated, it's possible for a invalid memory access to happen. Always set the deallocated scratch area to NULL after FLR completes.

VendorProductVersions

Linux

Linux

affected
98d187a989036096feaa2fef1ec3b2240ecdeacf - < 504c0e6751001ac46917c73e703f2b1b92cfc026
affected
98d187a989036096feaa2fef1ec3b2240ecdeacf - < 867d0c801f21370d561420fa32f2ea1a7dc3a22d
affected
98d187a989036096feaa2fef1ec3b2240ecdeacf - < d6077df7b75d26e4edf98983836c05d00ebabd8d

Linux

Linux

affected
6.14
unaffected
0 - < 6.14
unaffected
6.18.21 - <= 6.18.*
unaffected
6.19.11 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now