Resource exhaustion in Linux kernel - CVE-2026-31550
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper timeout handling in bcm2835_asb_control() when handling runtime power management suspend operations for V3D. A local user can trigger intensive workloads to cause a denial of service.
The issue can leave V3D in a broken state, leading to bus faults or system hangs on later accesses.
How to mitigate CVE-2026-31550
Sources
- https://git.kernel.org/stable/c/0e84e74849d2d7e9b23a09c2d5e0d9357db1ca59
- https://git.kernel.org/stable/c/18605b1b936b66b1f34dcf8e9ad4f1fbcf7a7c13
- https://git.kernel.org/stable/c/572f17180f26619809b8e0593d926762aa8660ff
- https://git.kernel.org/stable/c/622ab02e955c35c125ff2b65d8327b2c52db8758
- https://git.kernel.org/stable/c/9443202d91388026dbf7312972a74fbfd27ee82f
- https://git.kernel.org/stable/c/b826d2c0b0ecb844c84431ba6b502e744f5d919a
- https://git.kernel.org/stable/c/c5e734f6a0740dce92e7c919e632cb43fa5d4e53
- https://git.kernel.org/stable/c/ea4fa54b83bb2e4a21e9026824bfe271b1a6ee1e