cbcvebase.
CVE-2026-31558
published 2026-04-24

CVE-2026-31558: In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a…

PriorityP344high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so cpuid can be negative. Let kvm_get_vcpu_by_cpuid() return NULL for this case so as to make it more robust. This fix an out-of-bounds access to kvm_arch::phyid_map::phys_map[].

Affected

10 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 73516e9da512adc63ba3859fbd82a21f6257348f < 596c3f8069c4792f22fce8c4452f44410032d910596c3f8069c4792f22fce8c4452f44410032d910
linuxlinux>= 73516e9da512adc63ba3859fbd82a21f6257348f < 878cf6acb4fd8ab4126cf9d369a5bb0e23123418878cf6acb4fd8ab4126cf9d369a5bb0e23123418
linuxlinux>= 73516e9da512adc63ba3859fbd82a21f6257348f < 47857b05bd50db01e211a1b6f513d57901cd3e6b47857b05bd50db01e211a1b6f513d57901cd3e6b
linuxlinux>= 73516e9da512adc63ba3859fbd82a21f6257348f < 2db06c15d8c7a0ccb6108524e16cd9163753f3542db06c15d8c7a0ccb6108524e16cd9163753f354
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.10.1 < 6.12.806.12.80
linuxlinux_kernel>= 6.13 < 6.18.216.18.21
linuxlinux_kernel>= 6.19 < 6.19.116.19.11
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.