PT-2026-34996 · Linux · Linux Kernel

CVE-2026-31644

·

Published

2026-04-09

·

Updated

2026-05-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free and memory leak issue exists in the lan966x fdma reload() function. When the function fails to allocate new RX buffers, the restore path restarts DMA using old descriptors whose pages were already freed via lan966x fdma rx free pages(). Because page pool put full page() can release pages back to the buddy allocator, the hardware may perform DMA into memory owned by other kernel subsystems. Additionally, if allocation partially succeeds, the newly created page pool is overwritten without being destroyed, resulting in a memory leak.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12594
CVE-2026-31644
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1

Affected Products

Linux Kernel