Junglewise Threat Intelligence

CVE-2026-31588: Linux Kernel KVM use-after-free in x86 MMIO emulation

CVE-2026-31588 · Severity: high · CVSS 8.8 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's virtualization component (KVM) that could allow a local attacker to compromise the host system. The issue occurs when the system handles specific memory operations that span across different memory pages, leading to a memory error. This could potentially allow an attacker to gain unauthorized access to sensitive data or take control of the underlying server.

Technical details

A use-after-free vulnerability exists in the Linux kernel KVM x86 emulator when servicing emulated MMIO writes that split across page boundaries. When a write operation spans two MMIO pages, KVM splits the request into fragments. If the emulator uses an on-stack local variable as the source for the write, a second userspace exit (KVM_RUN) may reference that variable after it has been freed from the stack. This is particularly exploitable if a separate task performs the second KVM_RUN, accessing the stale stack memory. The fix involves copying small write values (8 bytes or less) into a persistent scratch field within the MMIO fragment instead of maintaining a pointer to the original stack-based source.

Affected products

  • Linux Linux Kernel 6.13 to 6.18.24, 6.19 to 6.19.14

Timeline

  • 2026-04-24: advisory: CVE-2026-31588 published
  • 2026-06-01: patched: Fix committed to stable tree

References

Related threats