Use-after-free in Linux kernel - CVE-2026-31501
Published: April 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the RX path timestamp handling in the icssg-prueth driver when processing received packets through the timestamp path. A local user can trigger packet processing that reaches the timestamp path to cause a denial of service.
Affected software
Ubuntu
linux-azure-6.17 (Ubuntu package)
linux-oracle-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
How to mitigate CVE-2026-31501
linux-azure-6.17 (Ubuntu package) - addressed in versions 6.17.0-42.42+1, 6.17.0-1019.22, 6.17.0-1022.22, 6.17.0-1022.25, 6.17.0-1032.32
linux-oracle-6.17 (Ubuntu package) - update to 6.17.0-1020.20
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1031.31