CVE-2026-31523Patch(linux / linux_kernel)

LOWCVSS 4.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A user can change the polled queue count at run time. There's a brief window during a reset where a hipri task may try to poll that queue before the block layer has updated the queue maps, which would race with the now interrupt driven queue and may cause double completions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 2Mentions · 2026-05-01: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-22: 2Technical Details · 2026-05-01: 104-2205-01
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-222
Disclosure1Patch1
2026-05-011
Patch1
Full discourse3 posts
  • Lorenzo Cavallaro@lcavallaro
    Patch

    So it happened that our own @bynar_io AI pipeline found and patched also a UAF in the Linux Kernel CAN subsystem (CVE-2026-31523). We're cooking more, on vulnerabilities, scientific positioning, and our own reflection on the whole software vulnerability ecosystem. Stay tuned.

    Post summary

    A UAF vulnerability (CVE‑2026‑31523) in the Linux Kernel CAN subsystem was identified and patched, but no PoC or exploit details are included.

    0001311.7K
    1.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31523 Race Condition in Linux Kernel NVMe-PCI Polled Queue Management During Reset https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31523

    Post summary

    The text announces a new race condition vulnerability in Linux Kernel NVMe‑PCI polled queue management, providing a brief technical description but no evidence of exploitation, PoC, or patch.

    0000084
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31523 In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A user can change the polled queue count at run ti… https://www.cve.org/CVERecord?id=CVE-2026-31523

    Post summary

    CVE‑2026‑31523, an issue in the Linux kernel’s nvme‑pci module related to polled queue count, has been fixed with a patch.

    00000110
    57.2K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more