CVE-2026-31574

Advisory lineage Upstream: 0 Downstream: 3
Analyzed
Published: 24 Apr 2026, 14:42
Last modified:11 May 2026, 22:11

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Apr 2026, 14:42
Published
Vulnerability first disclosed
11 May 2026, 22:11
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: clockevents: Add missing resets of the next_event_forced flag The prevention mechanism against timer interrupt starvation missed to reset the next_event_forced flag in a couple of places: - When the clock event state changes. That can cause the flag to be stale over a shutdown/startup sequence - When a non-forced event is armed, which then prevents rearming before that event. If that event is far out in the future this will cause missed timer interrupts. - In the suspend wakeup handler. That led to stalls which have been reported by several people. Add the missing resets, which fixes the problems for the reporters.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.02% Percentile: 4%

Affected Systems

  • linuxlinux

    ≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 9401b593fa48218d2667df1610b0ebc518554880 | ≥ d6e152d905bdb1f32f9d99775e2f453350399a6a, < 9401b593fa48218d2667df1610b0ebc518554880 | ≥ d6e152d905bdb1f32f9d99775e2f453350399a6a, < 4096fd0e8eaea13ebe5206700b33f49635ae18e5 | 7.0

  • linuxlinux_kernel

    < 7.0.1 | 7.0

References (2)