Junglewise Threat Intelligence

CVE-2026-31769: Linux Kernel use-after-free in GPIB IO ioctl handlers

CVE-2026-31769 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's General Purpose Interface Bus (GPIB) driver, which is used for communication with scientific and industrial instruments. A local attacker could exploit a flaw in how the system handles device input/output to cause a system crash or potentially execute unauthorized code. This issue stems from a race condition where the system tries to use a resource that has already been closed and freed.

Technical details

A use-after-free vulnerability exists in the Linux kernel GPIB driver due to improper reference counting in the IO ioctl handlers (IBRD, IBWRT, IBCMD, and IBWAIT). The vulnerability occurs because these handlers release the 'big_gpib_mutex' while still holding a pointer to a 'gpib_descriptor'. A concurrent 'IBCLOSEDEV' ioctl can then trigger 'close_dev_ioctl()', which frees the descriptor while it is still in use by the IO handlers. An attacker with local access can exploit this race condition to cause memory corruption. The fix introduces a 'descriptor_busy' reference counter to ensure the descriptor is not freed while IO operations are active.

Affected products

  • Linux Linux Kernel 6.13 to 6.18.22, 6.19 to 6.19.12, 7.0-rc1 to 7.0-rc6

Timeline

  • 2026-05-01: advisory: Initial disclosure of CVE-2026-31769
  • 2026-04-11: patched: Fix committed to stable kernel trees by Greg Kroah-Hartman

References

Related threats