Race condition in Linux kernel - CVE-2026-31740
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the rz-mtu3 counter sub-driver when probing shared hardware channels with the PWM sub-driver. A local user can trigger concurrent or ordered driver probing to cause a denial of service.
The issue affects channels shared between the counter and PWM drivers, where the counter sub-driver may perform runtime PM actions on the wrong device instance depending on probe order.
How to mitigate CVE-2026-31740
Sources
- https://git.kernel.org/stable/c/28a371be901ef44ee03726c2575d7d6795521fe0
- https://git.kernel.org/stable/c/2932095c114b98cbb40ccf34fc00d613cb17cead
- https://git.kernel.org/stable/c/633dfbf0eb2766c597c1a59dd83035c82e14791d
- https://git.kernel.org/stable/c/63be324c795262f0e316c6fe9b329d83afa1ec93
- https://git.kernel.org/stable/c/6562290225c197e2e193a53de2a517815288dcd1