Junglewise Threat Intelligence

CVE-2026-31703: Linux Kernel use after free in inode_switch_wbs_work_fn

CVE-2026-31703 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's data-writing mechanism could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly manages memory while switching between different background tasks responsible for saving data to disk. This could lead to a 'use-after-free' condition, impacting the overall stability and security of the operating system.

Technical details

A use-after-free vulnerability exists in the Linux kernel's fs/fs-writeback.c within the inode_switch_wbs_work_fn() function. The root cause is a race condition where a writeback (wb) structure can be freed while a work item (switch_work) is still pending, due to the way the function loops while processing context items. An attacker with local access could exploit this flaw to trigger a kernel panic or potentially achieve arbitrary code execution. The fix involves removing the problematic loop to ensure that reference counts are handled correctly relative to the queued work. Patches have been released for multiple stable kernel branches including 6.18.y and 7.0.y.

Affected products

  • Linux Linux 6.18 to 6.18.25, 7.0 to 7.0.2

Timeline

  • 2026-04-13: disclosed: Initial patch submitted by Jan Kara
  • 2026-05-01: advisory: CVE-2026-31703 published

References