Junglewise Threat Intelligence

CVE-2026-31440: Linux Kernel memory leak in dmaengine idxd driver

CVE-2026-31440 · Severity: medium · CVSS 5.5 · Published 2026-04-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability exists in the Linux kernel's Intel Data Streaming Accelerator (IDXD) driver. When the device is removed or reset, the system may fail to release allocated memory, potentially leading to a gradual depletion of system resources. This could eventually cause system instability or a denial-of-service condition where the operating system can no longer function correctly.

Technical details

A memory leak (CWE-401) exists in the dmaengine idxd driver within the Linux kernel. During the device removal process, a hardware reset causes configuration registers to return to their default state (zero). The 'idxd_device_evl_free' function previously checked the 'evl_en' bit in the GENCFG register to determine if the event log was enabled before attempting deallocation. Because the reset clears this bit, the driver would skip the deallocation logic, leaking the allocated event log memory. The fix removes the register check and instead relies on the validity of the 'idxd->evl' pointer to trigger memory release. This is a local vulnerability that can be exploited to cause a denial-of-service through resource exhaustion.

Affected products

  • Linux Linux Kernel 6.4 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc5

Timeline

  • 2026-04-22: advisory: Initial disclosure of CVE-2026-31440
  • 2026-02-25: patched: Initial patch committed to mainline kernel
  • 2026-05-17: other: NVD record updated with enrichment data

References

Related threats