CVE-2026-31787Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. When userspace does a partial munmap() on a privcmd mapping, the kernel splits the VMA via __split_vma(). Since may_split is NULL, the split is allowed. vm_area_dup() copies vm_private_data (a pages array allocated in alloc_empty_pages()) into the new VMA without any fixup, because there is no .open callback. Both VMAs now point to the same pages array. When the unmapped portion is closed, privcmd_close() calls: - xen_unmap_domain_gfn_range() - xen_free_unpopulated_pages() - kvfree(pages) The surviving VMA still holds the dangling pointer. When it is later destroyed, the same sequence runs again, which leads to a double free. Fix this issue by adding a .may_split callback denying the VMA split. This is XSA-487 / CVE-2026-31787

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-29: 1Mentions · 2026-05-01: 1Technical Details · 2026-04-29: 104-2905-01
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-05-011
General1
Full discourse2 posts
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting Linux Kernel (CVE-2026-31787) https://vuldb.com/vuln/360295

    Post summary

    The post announces that CVE-2026-31787, an important Linux kernel vulnerability, has been added to a vulnerability database, but no additional details are provided.

    01021135
    2.3K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Xen 487 v2 (CVE-2026-31787): Linux kernel double free in Xen privcmd driver https://www.openwall.com/lists/oss-security/2026/04/28/14 489 v1 (5 CVEs): Multiple RBAC issues in XAPI https://www.openwall.com/lists/oss-security/2026/04/28/18 The researcher claimed 89 vulnerabilities. [...] Due to acting in bad faith, they are explicitly not credited.

    Post summary

    The text announces several Xen-related CVEs, describing specific vulnerability types (double free and RBAC issues), but provides no PoC, exploit code, patch, or evidence of active exploitation.

    01030322
    4.7K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more