CVE-2026-31486Patch(linux / linux_kernel)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) Protect regulator operations with mutex The regulator operations pmbus_regulator_get_voltage(), pmbus_regulator_set_voltage(), and pmbus_regulator_list_voltage() access PMBus registers and shared data but were not protected by the update_lock mutex. This could lead to race conditions. However, adding mutex protection directly to these functions causes a deadlock because pmbus_regulator_notify() (which calls regulator_notifier_call_chain()) is often called with the mutex already held (e.g., from pmbus_fault_handler()). If a regulator callback then calls one of the now-protected voltage functions, it will attempt to acquire the same mutex. Rework pmbus_regulator_notify() to utilize a worker function to send notifications outside of the mutex protection. Events are stored as atomics in a per-page bitmask and processed by the worker. Initialize the worker and its associated data during regulator registration, and ensure it is cancelled on device removal using devm_add_action_or_reset(). While at it, remove the unnecessary include of linux/of.h.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-667

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-23: 104-2204-23
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • WindowsForum@windowsforum
    Patch

    🪟 Linux kernel fix for CVE-2026-31486: not a flashy hack, just deadlock chaos from missing update_lock. Concurrency > clever exploits. Meanwhile Windows still fights “works on my machine.” https://windowsforum.com/threads/cve-2026-31486-linux-pmbus-deadlock-fix-shows-concurrency-matters.414742/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #ConcurrencyBug #Cve2026 #PmbusRegulator https://t.co/QvLvuGYbYc

    Post summary

    The tweet highlights the Linux kernel fix for CVE-2026-31486, detailing a concurrency‑related deadlock issue and noting the patch, with no evidence of exploitation or PoC.

    0000057
    1.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31486 In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) Protect regulator operations with mutex The regulator operations pmbus_regul… https://www.cve.org/CVERecord?id=CVE-2026-31486

    Post summary

    CVE-2026-31486 has been fixed in the Linux kernel; the post notes the resolution but offers no technical details.

    00000122
    57.2K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel3.19--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more