Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-31442

25
FAUCET Score

CVE-2026-31442 is a memory management vulnerability in the Linux kernel's DMA engine IDXD driver that occurs during Function Level Reset (FLR) operations. Specifically, when a second FLR is initiated following a successful first FLR but fails to allocate scratch space for configuration storage, the system may attempt to access previously deallocated memory, affecting systems running the vulnerable Linux kernel versions with IDXD support. The vulnerability carries a CVSS score that is not yet publicly disclosed, though the EPSS score of 0.00017 indicates a very low probability of exploitation relative to other CVEs. The attack vector and complexity details are not specified in available data, but given its nature as a memory access flaw in kernel driver code, exploitation would likely require elevated privileges and specific hardware conditions involving repeated FLR sequences. There is no evidence of active exploitation or public exploit code availability. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog, and community attention appears minimal based on the inactive Hot List status. The issue has been resolved through a code patch that ensures deallocated scratch memory is properly set to NULL following each FLR completion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.14, < 6.18.21CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.19, < 6.19.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 13th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

git.kernel.org / stable/c/504c0e6751001ac46917c73e703f2b1b92cfc026
Patch
git.kernel.org / stable/c/867d0c801f21370d561420fa32f2ea1a7dc3a22d
Patch
git.kernel.org / stable/c/d6077df7b75d26e4edf98983836c05d00ebabd8d
Patch