PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31400 Linux CVE debrief

CVE-2026-31400 is a Linux kernel sunrpc memory-leak issue in cache_release(). If a reader closes its file descriptor while mid-read, the request can lose a reader without being freed, leaving the cache_request, its buffer, and cache_head reference behind. NVD assigns a medium CVSS score and lists the issue as affecting multiple Linux kernel release lines.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Linux kernel maintainers, distribution security teams, and operators of systems that use the sunrpc cache path should care most. Systems with local users or services that can interact with the affected kernel code path have the clearest exposure, and the CVSS vector reflects local, low-complexity prerequisites with high availability impact.

Technical summary

The bug is a cleanup omission in sunrpc cache_release(): when readers drops to zero after a file descriptor closes mid-read, the function decrements the reader count but does not perform the same dequeue-and-free logic that cache_read() uses. That means a cache_request can remain allocated if CACHE_PENDING already cleared before readers reached zero, because cache_dequeue() only frees requests when the pending state transitions at the right time. The result is a kernel memory leak rather than a confidentiality or integrity issue.

Defensive priority

Medium. The issue is availability-focused and locally reachable, so it is not an emergency zero-day scenario in the supplied record, but it can accumulate kernel memory until remediation is applied.

Recommended defensive actions

  • Apply the kernel fix referenced in the official stable patch links.
  • Prioritize updates for kernels within the vulnerable ranges listed by NVD.
  • Verify whether your deployed kernel branch has already backported the fix from stable.
  • Monitor affected systems for unexplained kernel memory growth if patching must be delayed.
  • Track downstream vendor advisories for the exact fixed build number in your distribution.

Evidence notes

The CVE record was published on 2026-04-03 and last modified on 2026-05-20, per the supplied timeline and NVD source item. The vulnerability description states that cache_release() decrements the readers count but fails to free the request when readers reaches zero and CACHE_PENDING is clear. NVD marks the weakness as CWE-401 and provides the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which supports a local availability-impacting memory leak. The official references include multiple kernel.org stable patch links.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31400 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31400

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31400 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31400

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/17ad31b3a43b72aec3a3d83605891e1397d0d065

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1dfedb293943e491379c9302b428e6f920a73d12

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/301670dcd098c1fe5c2fe90fb3c7a8f4814d2351

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/373457de14281c1fc7cace6fc4c8a267fc176673

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/41f6ba6c98a618043d2cd71030bf9a752dfab8b2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7bcd5e318876ac638c8ceade7a648e76ac8c48e1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/be5c35960e5ead70862736161836e2d1bc7352dc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.