PatchSiren cyber security CVE debrief
CVE-2026-31400 Linux CVE debrief
CVE-2026-31400 is a Linux kernel sunrpc memory-leak issue in cache_release(). If a reader closes its file descriptor while mid-read, the request can lose a reader without being freed, leaving the cache_request, its buffer, and cache_head reference behind. NVD assigns a medium CVSS score and lists the issue as affecting multiple Linux kernel release lines.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Linux kernel maintainers, distribution security teams, and operators of systems that use the sunrpc cache path should care most. Systems with local users or services that can interact with the affected kernel code path have the clearest exposure, and the CVSS vector reflects local, low-complexity prerequisites with high availability impact.
Technical summary
The bug is a cleanup omission in sunrpc cache_release(): when readers drops to zero after a file descriptor closes mid-read, the function decrements the reader count but does not perform the same dequeue-and-free logic that cache_read() uses. That means a cache_request can remain allocated if CACHE_PENDING already cleared before readers reached zero, because cache_dequeue() only frees requests when the pending state transitions at the right time. The result is a kernel memory leak rather than a confidentiality or integrity issue.
Defensive priority
Medium. The issue is availability-focused and locally reachable, so it is not an emergency zero-day scenario in the supplied record, but it can accumulate kernel memory until remediation is applied.
Recommended defensive actions
- Apply the kernel fix referenced in the official stable patch links.
- Prioritize updates for kernels within the vulnerable ranges listed by NVD.
- Verify whether your deployed kernel branch has already backported the fix from stable.
- Monitor affected systems for unexplained kernel memory growth if patching must be delayed.
- Track downstream vendor advisories for the exact fixed build number in your distribution.
Evidence notes
The CVE record was published on 2026-04-03 and last modified on 2026-05-20, per the supplied timeline and NVD source item. The vulnerability description states that cache_release() decrements the readers count but fails to free the request when readers reaches zero and CACHE_PENDING is clear. NVD marks the weakness as CWE-401 and provides the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which supports a local availability-impacting memory leak. The official references include multiple kernel.org stable patch links.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31400 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31400
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31400 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31400
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/17ad31b3a43b72aec3a3d83605891e1397d0d065
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1dfedb293943e491379c9302b428e6f920a73d12
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/301670dcd098c1fe5c2fe90fb3c7a8f4814d2351
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/373457de14281c1fc7cace6fc4c8a267fc176673
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/41f6ba6c98a618043d2cd71030bf9a752dfab8b2
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7bcd5e318876ac638c8ceade7a648e76ac8c48e1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/be5c35960e5ead70862736161836e2d1bc7352dc
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.