Allocation of Resources Without Limits or Throttling in Linux kernel - CVE-2026-31670
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the rfkill event handling logic when userspace creates rfkill events without consuming them from the rfkill file descriptor. A local user can create an unlimited number of pending rfkill events to cause a denial of service.
The issue can lead to an out-of-memory condition on systems configured to allow userspace to create such events.
How to mitigate CVE-2026-31670
Sources
- https://git.kernel.org/stable/c/4bcd1615a4e2a185ae9edd27b4143d7dfa7134f4
- https://git.kernel.org/stable/c/673d2a3eef6e0ee9736501a150c9e4024a4e60a6
- https://git.kernel.org/stable/c/80ce4cb026f0a4c4532b6cad827b44debda6256a
- https://git.kernel.org/stable/c/82843afc19012a29ba863961ef494165aa1a88f4
- https://git.kernel.org/stable/c/a8c26800e0220e1550af012f5a20e50f5c78864d
- https://git.kernel.org/stable/c/b1e0c8d3ab58a0161db487bf5fc47adfcaf5d5ca
- https://git.kernel.org/stable/c/e3842779547c83150569071d9980517cc9029fc0
- https://git.kernel.org/stable/c/ea245d78dec594372e27d8c79616baf49e98a4a1