CVE Database
/

CVE-2026-31782

Back to search

CVE-2026-31782

Published: May 1, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Fix potential bad container_of in intel_pmu_hw_config Auto counter reload may have a group of events with software events present within it. The software event PMU isn't the x86_hybrid_pmu and a container_of operation in intel_pmu_set_acr_caused_constr (via the hybrid helper) could cause out of bound memory reads. Avoid this by guarding the call to intel_pmu_set_acr_caused_constr with an is_x86_event check.

VendorProductVersions

Linux

Linux

affected
ec980e4facef8110f6fce27e5b6344660117f01f - < e435a30ca6fe14c9611b1fc731c98a6d28410247
affected
ec980e4facef8110f6fce27e5b6344660117f01f - < bfee04838f636d064bc92075c65c95f739003804
affected
ec980e4facef8110f6fce27e5b6344660117f01f - < dbde07f06226438cd2cf1179745fa1bec5d8914a

Linux

Linux

affected
6.16
unaffected
0 - < 6.16
unaffected
6.18.22 - <= 6.18.*
unaffected
6.19.12 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now