Improper control of a resource through its lifetime in Linux kernel - CVE-2026-31545
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource handling in the nxp-nci driver GPIO handling logic when operating GPIOs connected to I2C GPIO expanders. A local user can trigger the vulnerable code path to cause a denial of service.
The issue results in a kernel WARN_ON condition.
How to mitigate CVE-2026-31545
Sources
- https://git.kernel.org/stable/c/0c2320c3c860d281cbc2f49fc574c1947a6b9e2a
- https://git.kernel.org/stable/c/2a175bc3c338c6b2bc55004e93dd35a2467bdca2
- https://git.kernel.org/stable/c/4de9ed2ea22d611b4149969266b45a86ea8daf35
- https://git.kernel.org/stable/c/548a1bfe591364e63bce4af7c5802bb434efdaf8
- https://git.kernel.org/stable/c/55dc632ab2ac2889b15995a9eef56c753d48ebc7
- https://git.kernel.org/stable/c/70662874f646871c2f08ef1cf2544ba9a5f71b96
- https://git.kernel.org/stable/c/783f05e560d761dee7ff602b97edb0e54f2e9727
- https://git.kernel.org/stable/c/c24dcac1a9d1b4fd164898df0c2f5b0adbf81a78