Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-31482
Published: April 24, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper clearing of sensitive information in s390 kernel entry handlers when handling kernel entry. A local user can observe residual register contents to disclose sensitive information.
The issue affects the r12 register on s390 systems.
How to mitigate CVE-2026-31482
Sources
- https://git.kernel.org/stable/c/0738d395aab8fae3b5a3ad3fc640630c91693c27
- https://git.kernel.org/stable/c/7f4e3233faa8470dd0627bc49b2809f2bfebd909
- https://git.kernel.org/stable/c/95c899cd791803a5bf7b73e5994fbbe1cc1a9c36
- https://git.kernel.org/stable/c/99a8b420f3f0e162eb9c9c9253929d4d23f9bd30
- https://git.kernel.org/stable/c/a58d298a83a3a9b7ca99ded9d60a1e77231159ef