Race condition in Linux kernel - CVE-2026-31572

 

Race condition in Linux kernel - CVE-2026-31572

Published: April 25, 2026


Vulnerability identifier: #VU127830
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31572
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition leading to a NULL pointer dereference in the amdisp i2c device probe path when resuming the device during probe initialization. A local user can trigger the affected probe and resume sequence to cause a denial of service.

The issue occurs because runtime resume can be invoked before probe completion while the ISP power state is being managed.


Affected software

Linux kernel

How to mitigate CVE-2026-31572

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins