cbcvebase.
CVE-2026-31390
published 2026-04-03

CVE-2026-31390: In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() validation…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.6th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() validation fails, jump to the new free_vmas cleanup label to properly free the allocated resources. This ensures proper cleanup in this error path. (cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= 293032eec4baa04374d62dd44de61e355296ad32 < c3aa7b837920c844d5ae0dd3dbaeb465a461de40c3aa7b837920c844d5ae0dd3dbaeb465a461de40
linuxlinux>= 293032eec4baa04374d62dd44de61e355296ad32 < 1c87b48a0ff040723f84a67b32892af7e6a3634f1c87b48a0ff040723f84a67b32892af7e6a3634f
linuxlinux>= 293032eec4baa04374d62dd44de61e355296ad32 < 0cfe9c4838f1147713f6b5c02094cd4dc0c598fa0cfe9c4838f1147713f6b5c02094cd4dc0c598fa
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 6.18 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.