CVE-2026-31558
published 2026-04-24CVE-2026-31558: In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a…
PriorityP344high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so
cpuid can be negative. Let kvm_get_vcpu_by_cpuid() return NULL for this
case so as to make it more robust.
This fix an out-of-bounds access to kvm_arch::phyid_map::phys_map[].
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 73516e9da512adc63ba3859fbd82a21f6257348f < 596c3f8069c4792f22fce8c4452f44410032d910 | 596c3f8069c4792f22fce8c4452f44410032d910 |
| linux | linux | >= 73516e9da512adc63ba3859fbd82a21f6257348f < 878cf6acb4fd8ab4126cf9d369a5bb0e23123418 | 878cf6acb4fd8ab4126cf9d369a5bb0e23123418 |
| linux | linux | >= 73516e9da512adc63ba3859fbd82a21f6257348f < 47857b05bd50db01e211a1b6f513d57901cd3e6b | 47857b05bd50db01e211a1b6f513d57901cd3e6b |
| linux | linux | >= 73516e9da512adc63ba3859fbd82a21f6257348f < 2db06c15d8c7a0ccb6108524e16cd9163753f354 | 2db06c15d8c7a0ccb6108524e16cd9163753f354 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.10.1 < 6.12.80 | 6.12.80 |
| linux | linux_kernel | >= 6.13 < 6.18.21 | 6.18.21 |
| linux | linux_kernel | >= 6.19 < 6.19.11 | 6.19.11 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
vendor_redhat·2026-04-24
CVE-2026-31558 CWE-839 kernel: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
kernel: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component. A local attacker could potentially trigger an out-of-bounds memory access by providing a negative 'cpuid' parameter to the 'kvm_get_vcpu_by_cpuid()' function. This could lead to system instability or potentially other impacts due to memory corruption.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Ha
GHSA
GHSA-75vg-fcxx-gf7x: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
kvm_get_vcpu_by_cpuid()
ghsa_unreviewed·2026-04-24
CVE-2026-31558 GHSA-75vg-fcxx-gf7x: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
kvm_get_vcpu_by_cpuid()
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust
kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so
cpuid can be negative. Let kvm_get_vcpu_by_cpuid() return NULL for this
case so as to make it more robust.
This fix an out-of-bounds access to kvm_arch::phyid_map::phys_map[].
No detection rules found.
No public exploits indexed.
2026-04-24
Published