NULL pointer dereference in Linux kernel - CVE-2026-31481
Published: April 24, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of deferred trigger frees in tracing when processing crafted boot-time trace trigger parameters. A local user can supply specially crafted kernel command-line trace trigger settings to cause a denial of service.
Exploitation requires control over the kernel command line during boot.