Out-of-bounds read in Linux kernel - CVE-2026-31528
Published: April 24, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds memory access in x86_pmu_del() when rolling back a failed group_sched_in() operation for a group whose leader is a software event. A local user can trigger a failed group scheduling operation to cause a denial of service.
The issue occurs because inherited events may use the wrong PMU context for grouped events.
How to mitigate CVE-2026-31528
Sources
- https://git.kernel.org/stable/c/35f7914e54fe7f13654c22ee045b05e4b6d8062b
- https://git.kernel.org/stable/c/3a696e84a8b1fafdd774bb30d62919faf844d9e4
- https://git.kernel.org/stable/c/4b9ce671960627b2505b3f64742544ae9801df97
- https://git.kernel.org/stable/c/4c759446046500a1a6785b25725725c3ff087ace
- https://git.kernel.org/stable/c/656f35b463995bee024d948440128230aacd81e1