Use-after-free in Linux kernel - CVE-2026-31650

 

Use-after-free in Linux kernel - CVE-2026-31650

Published: April 25, 2026


Vulnerability identifier: #VU127745
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31650
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the vub300 driver controller allocation and lifetime handling when disconnecting or unbinding the driver. A local user can trigger driver unbinding or device disconnect handling to cause a denial of service.

The issue can also result in memory leaks when the driver is unbound without the USB device being physically disconnected.


Affected software

Linux kernel

How to mitigate CVE-2026-31650

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins