Use-after-free in Linux kernel - CVE-2026-31644
Published: April 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in lan966x_fdma_reload() when handling a failure to allocate new RX buffers during DMA reload. A local user can trigger the allocation failure and restart DMA with old descriptors whose pages were already freed to cause a denial of service.
The issue occurs on the restore path, where hardware may DMA into memory that has been returned to the buddy allocator and reused by other kernel subsystems.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-31644
linux (Debian package) - update to 6.12.85-1