Junglewise Threat Intelligence

CVE-2026-31436: Linux Kernel IDXD driver NULL pointer dereference in llist_abort_desc

CVE-2026-31436 · Severity: critical · CVSS 9.8 · Published 2026-04-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's data movement engine (dmaengine) specifically affecting Intel's Data Streaming Accelerator (IDXD) driver. This component is responsible for high-performance data transfers and cryptographic acceleration. An exploit could lead to system instability, data corruption, or a complete system crash, potentially impacting business operations and service availability.

Technical details

A logic error exists in the 'llist_abort_desc()' function within the 'drivers/dma/idxd/submit.c' component of the Linux kernel. During the abort process, the code incorrectly references a static 'found' descriptor instead of the current traversal cursor 'd' during a list loop. This mismatch can result in NULL pointer dereferences, double completion of descriptors, or descriptor leaks. An attacker could potentially leverage this to cause a Denial of Service (DoS) or achieve arbitrary code execution. Patches have been released for multiple stable kernel branches including 6.12.y, 6.18.y, and 6.19.y.

Affected products

  • Linux Linux Kernel 6.8 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc6

Timeline

  • 2026-01-06: other: Vulnerability reported/fixed in upstream code
  • 2026-04-22: disclosed: Initial publication date
  • 2026-04-22: advisory: Advisory published by kernel.org
  • 2026-05-19: other: NVD analysis and CPE enrichment

References

Related threats