CVE-2026-31442 is a memory management vulnerability in the Linux kernel's DMA engine IDXD driver that occurs during Function Level Reset (FLR) operations. Specifically, when a second FLR is initiated following a successful first FLR but fails to allocate scratch space for configuration storage, the system may attempt to access previously deallocated memory, affecting systems running the vulnerable Linux kernel versions with IDXD support. The vulnerability carries a CVSS score that is not yet publicly disclosed, though the EPSS score of 0.00017 indicates a very low probability of exploitation relative to other CVEs. The attack vector and complexity details are not specified in available data, but given its nature as a memory access flaw in kernel driver code, exploitation would likely require elevated privileges and specific hardware conditions involving repeated FLR sequences. There is no evidence of active exploitation or public exploit code availability. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog, and community attention appears minimal based on the inactive Hot List status. The issue has been resolved through a code patch that ensures deallocated scratch memory is properly set to NULL following each FLR completion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.14, < 6.18.21CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.