CVE-2026-31398 is a vulnerability in the Linux kernel's memory management (mm/rmap) that can lead to a kernel crash. The flaw occurs due to incorrect page table entry (PTE) restoration for lazyfree folios, where a batch of mixed writable and non-writable PTEs may be erroneously set entirely writable, violating Copy-on-Write semantics. This issue can be triggered by specific memory manipulation techniques, resulting in a Denial of Service (DoS). While a proof-of-concept reproducer is available, there is no indication of active exploitation, and it is not listed on CISA's Known Exploited Vulnerabilities catalog. Community discussion and media coverage for this CVE are currently low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.15, < 6.18.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.