cbcvebase.
CVE-2026-31576
published 2026-04-24

CVE-2026-31576: In the Linux kernel, the following vulnerability has been resolved: media: hackrf: fix to not free memory after the device is registered in hackrf_probe() In…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.8th percentile
In the Linux kernel, the following vulnerability has been resolved: media: hackrf: fix to not free memory after the device is registered in hackrf_probe() In hackrf driver, the following race condition occurs: ``` CPU0 CPU1 hackrf_probe() kzalloc(); // alloc hackrf_dev .... v4l2_device_register(); .... fd = sys_open("/path/to/dev"); // open hackrf fd .... v4l2_device_unregister(); .... kfree(); // free hackrf_dev .... sys_ioctl(fd, ...); v4l2_ioctl(); video_is_registered() // UAF!! .... sys_close(fd); v4l2_release() // UAF!! hackrf_video_release() kfree(); // DFB!! ``` When a V4L2 or video device is unregistered, the device node is removed so new open() calls are blocked. However, file descriptors that are already open-and any in-flight I/O-do not terminate immediately; they remain valid until the last reference is dropped and the driver's release() is invoked. Therefore, freeing device memory on the error path after hackrf_probe() has registered dev it will lead to a race to use-after-free vuln, since those already-open handles haven't been released yet. And since release() free memory too, race to use-after-free and double-free vuln occur. To prevent this, if device is registered from probe(), it should be modified to free memory only through release() rather than calling kfree() directly.

Affected

23 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 87b9685cca91ed715c39ba544715832d26a7f4b487b9685cca91ed715c39ba544715832d26a7f4b4
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 131ec9046e1c8af101aebdaec4e8095e05f3312b131ec9046e1c8af101aebdaec4e8095e05f3312b
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 67fd62e3efdc9dce01f76d95a745212f4feb38e667fd62e3efdc9dce01f76d95a745212f4feb38e6
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 45cbaf5c7cdc5386d86377f0daf94a17a007fed045cbaf5c7cdc5386d86377f0daf94a17a007fed0
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 98a0a81ce78020c2522e0046f49d200de9778cb998a0a81ce78020c2522e0046f49d200de9778cb9
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 07e9e674b6146b1f6fc41b1f54b8968bf280282407e9e674b6146b1f6fc41b1f54b8968bf2802824
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 2145c71a8044362e82e9923f001ba2aeb771b8482145c71a8044362e82e9923f001ba2aeb771b848
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < fcd1d70792a35c8a97414fe429f48311e41269c2fcd1d70792a35c8a97414fe429f48311e41269c2
linuxlinux>= 8bc4a9ed85046c214458c9e82aea75d2f46cfffd < 3b7da2b4d0fe014eff181ed37e3bf832eb8ed2583b7da2b4d0fe014eff181ed37e3bf832eb8ed258
linuxlinux_kernel< 6.6.1366.6.136
linuxlinux_kernel>= 6.13 < 6.18.246.18.24
linuxlinux_kernel>= 6.19 < 6.19.146.19.14
linuxlinux_kernel>= 6.7 < 6.12.836.12.83
linuxlinux_kernel>= 7.0 < 7.0.17.0.1
ubuntulinux
ubuntulinux-aws
ubuntulinux-gcp
ubuntulinux-ibm
ubuntulinux-nvidia
ubuntulinux-oracle
ubuntulinux-raspi
ubuntulinux-realtime

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.