CVE-2026-31399

In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingisoul with KASAN reports a use after free if device_add() fails in nd_async_device_register(). Commit b6eae0f61db2 ("libnvdimm: Hold reference on parent while scheduling async init") correctly added a reference on the parent device to be held until asynchronous initialization was complete. However, if device_add() results in an allocation failure the ref count of the device drops to 0 prior to the parent pointer being accessed. Thus resulting in use after free. The bug bot AI correctly identified the fix. Save a reference to the parent pointer to be used to drop the parent reference regardless of the outcome of device_add().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: nvdimm/bus: Soluciona un posible uso después de liberar en la inicialización asíncrona Dingisoul con KASAN informa de un uso después de liberar si device_add() falla en nd_async_device_register(). El commit b6eae0f61db2 ('libnvdimm: Mantener referencia en el padre mientras se programa la inicialización asíncrona') añadió correctamente una referencia en el dispositivo padre para ser mantenida hasta que la inicialización asíncrona estuviera completa. Sin embargo, si device_add() resulta en un fallo de asignación, el contador de referencias del dispositivo cae a 0 antes de que se acceda al puntero padre. Resultando así en un uso después de liberar. La IA del bot de errores identificó correctamente la solución. Guarda una referencia al puntero padre para ser utilizada para liberar la referencia padre independientemente del resultado de device_add().

20 May 2026, 12:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-416
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/2c638259ad750833fd46a0cf57672a618542d84c - () https://git.kernel.org/stable/c/2c638259ad750833fd46a0cf57672a618542d84c - Patch
References () https://git.kernel.org/stable/c/6fc36c2a925ceaba203eb13d75a8f0879a2c121b - () https://git.kernel.org/stable/c/6fc36c2a925ceaba203eb13d75a8f0879a2c121b - Patch
References () https://git.kernel.org/stable/c/84af19855d1abdee3c9d57c0684e2868e391793c - () https://git.kernel.org/stable/c/84af19855d1abdee3c9d57c0684e2868e391793c - Patch
References () https://git.kernel.org/stable/c/9a0fb16ba5b372465a3a1ecd761c6fa911a4ab4d - () https://git.kernel.org/stable/c/9a0fb16ba5b372465a3a1ecd761c6fa911a4ab4d - Patch
References () https://git.kernel.org/stable/c/a226e5b49e5fe8c98b14f8507de670189d191348 - () https://git.kernel.org/stable/c/a226e5b49e5fe8c98b14f8507de670189d191348 - Patch
References () https://git.kernel.org/stable/c/a36cf138500e56f50db9f9a33222df6969b38326 - () https://git.kernel.org/stable/c/a36cf138500e56f50db9f9a33222df6969b38326 - Patch
References () https://git.kernel.org/stable/c/a8aec14230322ed8f1e8042b6d656c1631d41163 - () https://git.kernel.org/stable/c/a8aec14230322ed8f1e8042b6d656c1631d41163 - Patch
References () https://git.kernel.org/stable/c/e48bf8f1d2b12c1c5ba1f609edbd4cde5dadc20e - () https://git.kernel.org/stable/c/e48bf8f1d2b12c1c5ba1f609edbd4cde5dadc20e - Patch

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/6fc36c2a925ceaba203eb13d75a8f0879a2c121b -
  • () https://git.kernel.org/stable/c/a36cf138500e56f50db9f9a33222df6969b38326 -

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-31399

Mitre link : CVE-2026-31399

CVE.ORG link : CVE-2026-31399


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free