Improper resource shutdown or release in Linux kernel - CVE-2026-31655
Published: April 25, 2026
Vulnerability identifier: #VU127750
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-31655
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper power management in imx8mp-blk-ctrl when handling the NoC ADB400 port power down handshake. A local user can trigger the affected power management path to cause a denial of service.
How to mitigate CVE-2026-31655
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/3086374e8bc7fd65f2cc62ef52351c6d662f1543
- https://git.kernel.org/stable/c/80fd0de89805a3f92dc320f5ab5a18007c260374
- https://git.kernel.org/stable/c/d1ef779d02b5df4e8bff4083b20bfea587b43c4b
- https://git.kernel.org/stable/c/e44919669f07b8f113ad49a248b44ca4f119bc94
- https://git.kernel.org/stable/c/e91d5f94acf68618ea3ad9c92ac28614e791ae7d