Information disclosure in Linux kernel - CVE-2026-31628
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to improper isolation of partial divider results in x86 CPU handling when executing division operations on Zen1 processors. A local attacker can run a thread that observes residual partial results from previous operations to disclose sensitive information.
Exploitation requires another thread to access leaked partial results left by a previous operation under certain circumstances.
How to mitigate CVE-2026-31628
Sources
- https://git.kernel.org/stable/c/0548529af20e68c6552817834b766646dd3bd7a7
- https://git.kernel.org/stable/c/1272cfedf4cd1019ddf583917a99b62f2d3645bb
- https://git.kernel.org/stable/c/546785c719418c6166834a47e372a88f5f7ae893
- https://git.kernel.org/stable/c/91f02726b2203b71545713ecb7fb006e60a2d66f
- https://git.kernel.org/stable/c/ad17f07e95e6e8505e2153e5b391f0d27eacce25
- https://git.kernel.org/stable/c/b731aca06387b195058a9f6449a03b62efa1bd10
- https://git.kernel.org/stable/c/e6af5286efe5a56128b34032572c9ce9ebeccda3
- https://git.kernel.org/stable/c/ed7a3a246309ccc807238f1b4f159ee6d37ff9c4