Improper control of a resource through its lifetime in Linux kernel - CVE-2026-31735

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-31735

Published: May 2, 2026


Vulnerability identifier: #VU128954
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-31735
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper invalidation handling in the iommu unmap gather logic when unmapping a range that ends within the middle of a large or contiguous IOPTE. A local user can trigger an unmap operation in this condition to cause a denial of service.

The issue results from the invalidation range not being extended to cover the full unmapped area when unmap removes more memory than was originally requested.


How to mitigate CVE-2026-31735

Install security update from vendor's repository.

Sources