PT-2026-34998 · Linux+1 · Linux Kernel+1

CVE-2026-31646

·

Published

2026-04-24

·

Updated

2026-08-20

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A kernel oops occurs in the Linux kernel due to improper error handling in the lan966x fdma rx alloc page pool() function. The page pool create() function can return an ERR PTR upon failure, which is then used unconditionally in a subsequent loop. This error pointer is passed through xdp rxq info reg mem model() into page pool use xdp mem(), where it is dereferenced.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-83639
CVE-2026-31646
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linux Kernel
Ubuntu