PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31440 Linux CVE debrief

CVE-2026-31440 is a Linux kernel availability issue in the dmaengine idxd driver. NVD describes a memory leak in event log handling during device removal: if the device is reset first, configuration registers return to default zero values, and the driver's pre-free check can fail, leaving event log memory undeallocated. The published fix removes that fragile support check and relies on the event-log allocation state instead. NVD rates the issue MEDIUM (CVSS 5.5) and models it as a local, low-privilege availability impact.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-22
Original CVE updated
2026-05-17
Advisory published
2026-04-22
Advisory updated
2026-05-17

Who should care

Linux kernel maintainers, distro security teams, and operators running systems that use the idxd/dmaengine path should care, especially where device remove/reset events are part of normal administration or hot-plug workflows. Systems on affected kernel ranges should prioritize updating because the issue can consume kernel memory and degrade availability.

Technical summary

The vulnerability is a CWE-401 resource leak in the Linux kernel's idxd driver. During device removal, the device is reset and its configuration registers revert to zero. The buggy cleanup logic checked whether event-log support was enabled before freeing memory; after reset, that check could fail even though event-log memory had been allocated earlier. The result is leaked event log memory on the remove path. NVD's affected-version criteria include Linux kernel 6.4 before 6.12.80, 6.13 before 6.18.21, 6.19 before 6.19.11, and 7.0 release candidates rc1 through rc5.

Defensive priority

Medium priority. The issue is not rated critical, but it affects kernel availability and is fixed in upstream/stable references. Apply the kernel update promptly on affected builds, particularly if idxd is enabled or device remove/reset operations occur in production.

Recommended defensive actions

  • Upgrade to a kernel version that includes the referenced fix commits from the official kernel stable tree.
  • Identify whether your fleet uses the idxd driver or related dmaengine functionality and prioritize those hosts for remediation.
  • Review systems on affected ranges listed by NVD: 6.4 to before 6.12.80, 6.13 to before 6.18.21, 6.19 to before 6.19.11, and 7.0 rc1-rc5.
  • Monitor for unusual kernel memory growth or repeated device removal/reset activity on affected hosts until patched.
  • If immediate upgrading is not possible, reduce unnecessary device remove/reset operations on affected systems where operationally feasible.

Evidence notes

This debrief is based on the supplied CVE description and NVD metadata only. The source corpus states the defect occurs during device removal after a reset causes configuration registers to return to zero, preventing cleanup from freeing event log memory when the driver checks support state instead of allocation state. NVD classifies the weakness as CWE-401 and provides the affected kernel version ranges and official kernel patch references. No exploit details or unsupported impact claims are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31440 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31440

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31440 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31440

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/695b491dc3f20365fd5821f22e25dbe3c1c20cbc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9dfa00967e6ef43a9dd0887fe5c3a721a39da92e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d94f9b0ba28a205caf95902ee88b42bdb8af83d0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ee66bc29578391c9b48523dc9119af67bd5c7c0f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/facd0012708e942fc12890708738aebde497564e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.