CVE-2026-31501

Aliases:UBUNTU-CVE-2026-31501DEBIAN-CVE-2026-31501CGA-3h7r-c6vq-3m9fCGA-7q52-pvrf-429pCGA-cvqx-p822-wrv9CGA-f755-w75m-6jmjCGA-h7pj-3wvr-xjgfCGA-j8v4-9j5w-4m9gCGA-jr33-9875-hh8fCGA-p6wj-3823-3xmrCGA-vg85-hq85-3vcqCGA-vmw7-4vq5-6jr5CGA-w8pf-7jqr-p9xwCGA-xv86-9vjf-94f4CGA-qgfh-j2gv-75c9CGA-x34c-rq4c-54w5CGA-49r8-9qcv-j59xCGA-4v98-vxhp-jpjgCGA-79fj-72vf-v57fCGA-7g8h-g7f6-mq7qCGA-7jj6-mxv8-3f57CGA-995x-p36c-6qf8CGA-99g9-8jwq-3g84CGA-cvp7-hmfv-686rCGA-gfg3-79w8-pq6gCGA-pf35-r6v3-xq5wCGA-rf7m-x9v7-337wCGA-v7xr-qwqx-mpfx
Advisory lineage Upstream: 0 Downstream: 5
Analyzed
Published: 22 Apr 2026, 13:54
Last modified:05 Aug 2026, 12:23

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
0.38% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Apr 2026, 13:54
Published
Vulnerability first disclosed
05 Aug 2026, 12:23
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_hdesc_get_psdata() returns a pointer into the CPPI descriptor. In both emac_rx_packet() and emac_rx_packet_zc(), the descriptor is freed via k3_cppi_desc_pool_free() before the psdata pointer is used by emac_rx_timestamp(), which dereferences psdata[0] and psdata[1]. This constitutes a use-after-free on every received packet that goes through the timestamp path. Defer the descriptor free until after all accesses through the psdata pointer are complete. For emac_rx_packet(), move the free into the requeue label so both early-exit and success paths free the descriptor after all accesses are done. For emac_rx_packet_zc(), move the free to the end of the loop body after emac_dispatch_skb_zc() (which calls emac_rx_timestamp()) has returned.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.38% Percentile: 32%

Techniques & Countermeasures

  • CWE-416Use After Free

    The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Affected Systems

  • chainguardlinux-aws-6.18

    < 0

  • chainguardlinux-azure-6.18

    < 0

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.18

    < 0 | < 6.18.38-r2

  • chainguardlinux-gcp-6.18-bootc

    < 6.18.38-r2

  • chainguardlinux-gcp-6.18-bootc-boot-installed

    < 0

  • chainguardlinux-qemu-6.18

    < 6.18.38-r2 | < 0

  • chainguardlinux-qemu-6.18-bootc

    < 6.18.38-r2

  • chainguardlinux-qemu-6.18-bootc-boot-installed

    < 0

  • chainguardlinux-qemu-melange

    < 0

  • chainguardlinux-vmware-6.18

    < 0

  • debianlinux

    < 6.19.11-1

  • ubuntulinux

    all

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-azure

    all | all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.17

    < 6.17.0-1022.22

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-bluefield

    all

  • ubuntulinux-gcp

    all | all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

Showing first 50 affected entries in server-rendered view.

References (12)