CVE-2026-31788Disclosure(linux / linux_kernel)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xen privcmd driver allows to issue arbitrary hypercalls from user space processes. This is normally no problem, as access is usually limited to root and the hypervisor will deny any hypercalls affecting other domains. In case the guest is booted using secure boot, however, the privcmd driver would be enabling a root user process to modify e.g. kernel memory contents, thus breaking the secure boot feature. The only known case where an unprivileged domU is really needing to use the privcmd driver is the case when it is acting as the device model for another guest. In this case all hypercalls issued via the privcmd driver will target that other guest. Fortunately the privcmd driver can already be locked down to allow only hypercalls targeting a specific domain, but this mode can be activated from user land only today. The target domain can be obtained from Xenstore, so when not running in dom0 restrict the privcmd driver to that target domain from the beginning, resolving the potential problem of breaking secure boot. This is XSA-482 --- V2: - defer reading from Xenstore if Xenstore isn't ready yet (Jan Beulich) - wait in open() if target domain isn't known yet - issue message in case no target domain found (Jan Beulich)

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-03-24); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-04-25: 1Mentions · 2026-05-04: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-28: 1Technical Details · 2026-04-25: 103-2403-2503-2703-2804-2505-04
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-241
Disclosure1
2026-03-251
Disclosure1
2026-03-271
Disclosure1
2026-03-281
Disclosure1
2026-04-251
General1
2026-05-041
General1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Xen Security Advisory 482 v3 (CVE-2026-31788) - Linux privcmd driver can circumvent kernel lockdown https://www.openwall.com/lists/oss-security/2026/03/24/3 An administrator of an unprivileged guest booted in secure mode is able to perform actions on the [guest] kernel which should not be possible in secure mode

    Post summary

    The advisory announces CVE‑2026‑31788, revealing that the Linux privcmd driver in Xen can bypass kernel lockdown in a secure‑mode guest, allowing unauthorized privileged actions.

    01091551
    4.4K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    公開。 『PV, PVH and HVM guests running Linux using secure boot are vulnerable.』 XSA-482 - Xen Security Advisories CVE-2026-31788 Linux privcmd driver can circumvent kernel lockdown https://xenbits.xen.org/xsa/advisory-482.html

    Post summary

    The text announces CVE‑2026‑31788, noting that PV, PVH, and HVM Linux guests with secure boot can bypass kernel lockdown via the privcmd driver, as detailed in the Xen XSA‑482 advisory.

    00020373
    6.7K followersView on X
  • Willy Tarreau@WillyTarreau
    General

    @spendergrsec I don't know the context but a grep showed me this one got CVE-2026-31788 assigned. Maybe misunderstanding / timing issue ?

    Post summary

    The post merely notes that CVE‑2026‑31788 was assigned and hints at a possible misunderstanding, without providing details on exploitation, patches, or technical specifics.

    1000081
    2.6K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-31788: Linux Kernel Xen Privilege Escalation - What It Means for Your Business and How to Respond https://hubs.li/Q04dssm30

    Post summary

    The brief text announces CVE-2026-31788, a privilege escalation flaw in Linux Kernel Xen, and directs readers to a business-focused response guide without providing detailed technical or exploit information.

    0000028
    29 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-31788 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31788 #CVE-2026-31788 #CVE   #CyberSecurity #InfoSec https://t.co/iuDLdRSIm2

    Post summary

    A new CVE (CVE-2026-31788) has been announced with an unknown risk level and unspecified affected products, but no further details, PoC, exploit code, or patch information are provided.

    0000025
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31788 - xen/privcmd: restrict usage in unprivileged domU Intel Report: https://ift.tt/3xjJEAa

    Post summary

    The alert announces the newly disclosed CVE-2026-31788 affecting Xen’s privileged command handling in unprivileged domUs, providing a brief technical detail and a link to an Intel report.

    0000036
    286 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.37--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more