CVE-2026-31390
published 2026-04-03CVE-2026-31390: In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() validation…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix memory leak in xe_vm_madvise_ioctl
When check_bo_args_are_sane() validation fails, jump to the new
free_vmas cleanup label to properly free the allocated resources.
This ensures proper cleanup in this error path.
(cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.10-1 (forky) | linux 6.19.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 293032eec4baa04374d62dd44de61e355296ad32 < c3aa7b837920c844d5ae0dd3dbaeb465a461de40 | c3aa7b837920c844d5ae0dd3dbaeb465a461de40 |
| linux | linux | >= 293032eec4baa04374d62dd44de61e355296ad32 < 1c87b48a0ff040723f84a67b32892af7e6a3634f | 1c87b48a0ff040723f84a67b32892af7e6a3634f |
| linux | linux | >= 293032eec4baa04374d62dd44de61e355296ad32 < 0cfe9c4838f1147713f6b5c02094cd4dc0c598fa | 0cfe9c4838f1147713f6b5c02094cd4dc0c598fa |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.10-1 | 6.19.10-1 |
| linux | linux_kernel | >= 6.18 < 6.18.20 | 6.18.20 |
| linux | linux_kernel | >= 6.19 < 6.19.10 | 6.19.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fpjr-hm8v-68cj: In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix memory leak in xe_vm_madvise_ioctl
When check_bo_args_are_sane() val
ghsa_unreviewed·2026-04-03
CVE-2026-31390 GHSA-fpjr-hm8v-68cj: In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix memory leak in xe_vm_madvise_ioctl
When check_bo_args_are_sane() val
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix memory leak in xe_vm_madvise_ioctl
When check_bo_args_are_sane() validation fails, jump to the new
free_vmas cleanup label to properly free the allocated resources.
This ensures proper cleanup in this error path.
(cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)
OSV
CVE-2026-31390: In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() valid
osv·2026-04-03
CVE-2026-31390 CVE-2026-31390: In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() valid
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() validation fails, jump to the new free_vmas cleanup label to properly free the allocated resources. This ensures proper cleanup in this error path. (cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)
Red Hat
kernel: drm/xe: Fix memory leak in xe_vm_madvise_ioctl
vendor_redhat·2026-04-03·CVSS 5.5
CVE-2026-31390 [LOW] CWE-459 kernel: drm/xe: Fix memory leak in xe_vm_madvise_ioctl
kernel: drm/xe: Fix memory leak in xe_vm_madvise_ioctl
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix memory leak in xe_vm_madvise_ioctl
When check_bo_args_are_sane() validation fails, jump to the new
free_vmas cleanup label to properly free the allocated resources.
This ensures proper cleanup in this error path.
(cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)
A flaw was found in the Linux kernel's drm/xe component. A local user could exploit this vulnerability when validation fails during the `xe_vm_madvise_ioctl` operation, leading to improper cleanup of allocated resources. This can result in a memory leak, potentially causing system instability or a denial of service (DoS) over time.
Package: kernel (Red Hat Enterprise Linux 10)
Debian
CVE-2026-31390: linux - In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix...
vendor_debian·2026
CVE-2026-31390 [LOW] CVE-2026-31390: linux - In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix...
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() validation fails, jump to the new free_vmas cleanup label to properly free the allocated resources. This ensures proper cleanup in this error path. (cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.10-1)
sid: resolved (fixed in 6.19.10-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-31390 kernel: drm/xe: Fix memory leak in xe_vm_madvise_ioctl
bugzilla·2026-04-03·CVSS 5.5
CVE-2026-31390 [MEDIUM] CVE-2026-31390 kernel: drm/xe: Fix memory leak in xe_vm_madvise_ioctl
CVE-2026-31390 kernel: drm/xe: Fix memory leak in xe_vm_madvise_ioctl
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix memory leak in xe_vm_madvise_ioctl
When check_bo_args_are_sane() validation fails, jump to the new
free_vmas cleanup label to properly free the allocated resources.
This ensures proper cleanup in this error path.
(cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026040324-CVE-2026-31390-f363@gregkh/T
Wiz
CVE-2026-31390 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-31390 CVE-2026-31390 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-31390 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix memory leak in xe_vm_madvise_ioctl
When check_bo_args_are_sane() validation fails, jump to the new
free_vmas cleanup label to properly free the allocated resources.
This ensures proper cleanup in this error path.
(cherry picked from commit 29bd06faf727a4b76663e4be0f7d770e2d2a7965)
Source : NVD
Published April 3, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-gcp-fips
kernel-64k-debug-modules-i
2026-04-03
Published