CVE-2026-53031

In the Linux kernel, the following vulnerability has been resolved: bpf: Validate node_id in arena_alloc_pages() arena_alloc_pages() accepts a plain int node_id and forwards it through the entire allocation chain without any bounds checking. Validate node_id before passing it down the allocation chain in arena_alloc_pages().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

15 Jul 2026, 14:37

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/2845989f2ebaf7848e4eccf9a779daf3156ea0a5 - () https://git.kernel.org/stable/c/2845989f2ebaf7848e4eccf9a779daf3156ea0a5 - Patch
References () https://git.kernel.org/stable/c/31d3b4b28e55835646d6829d60023f730dd34e85 - () https://git.kernel.org/stable/c/31d3b4b28e55835646d6829d60023f730dd34e85 - Patch
References () https://git.kernel.org/stable/c/e15900888c09480a4c632bc598f1c5bd39bed6d6 - () https://git.kernel.org/stable/c/e15900888c09480a4c632bc598f1c5bd39bed6d6 - Patch
References () https://git.kernel.org/stable/c/fb66e20130f95a93ffea1677252526a9e39170b2 - () https://git.kernel.org/stable/c/fb66e20130f95a93ffea1677252526a9e39170b2 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo

28 Jun 2026, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

24 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 17:17

Updated : 2026-07-15 14:37


NVD link : CVE-2026-53031

Mitre link : CVE-2026-53031

CVE.ORG link : CVE-2026-53031


JSON object : View

Products Affected

linux

  • linux_kernel