« Volver al listado

CVE-2026-31399

Estado: AnalizadaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

nvdimm/bus: Fix potential use after free in asynchronous initialization

Dingisoul with KASAN reports a use after free if device_add() fails in nd_async_device_register().

Commit b6eae0f61db2 ("libnvdimm: Hold reference on parent while scheduling async init") correctly added a reference on the parent device to be held until asynchronous initialization was complete. However, if device_add() results in an allocation failure the ref count of the device drops to 0 prior to the parent pointer being accessed. Thus resulting in use after free.

Leer descripción completaMostrar menos

The bug bot AI correctly identified the fix. Save a reference to the parent pointer to be used to drop the parent reference regardless of the outcome of device_add().

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L, PR:L) de use-after-free en kernel Linux que permite escalada de privilegios (I:H); ejecución de código arbitrario como impacto principal (CWE-416 típicamente usado para RCE vía kernel).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-31399",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "6fc36c2a925ceaba203eb13d75a8f0879a2c121b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "a36cf138500e56f50db9f9a33222df6969b38326",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "9a0fb16ba5b372465a3a1ecd761c6fa911a4ab4d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "e48bf8f1d2b12c1c5ba1f609edbd4cde5dadc20e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "2c638259ad750833fd46a0cf57672a618542d84c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "a226e5b49e5fe8c98b14f8507de670189d191348",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "84af19855d1abdee3c9d57c0684e2868e391793c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6eae0f61db27748606cc00dafcfd1e2c032f0a5",
              "lessThan": "a8aec14230322ed8f1e8042b6d656c1631d41163",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8954771abdea5c34280870e35592c7226a816d95",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3e63a7f25cc85d3d3e174b9b0e3489ebb7eaf4ab",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1490de2bb0836fc0631c04d0559fdf81545b672f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e31a8418c8df7e6771414f99ed3d95ba8aca4e05",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f1a55a4f990016406147cf3e0c9487bf83e50f0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.4.164",
              "lessThan": "4.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.9.137",
              "lessThan": "4.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.14.81",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.18.19",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.2",
              "lessThan": "4.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/nvdimm/bus.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.20"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.253",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.203",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.167",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.130",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.78",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.20",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.10",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nvdimm/bus.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-04-03T16:16:38.410",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2c638259ad750833fd46a0cf57672a618542d84c",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6fc36c2a925ceaba203eb13d75a8f0879a2c121b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84af19855d1abdee3c9d57c0684e2868e391793c",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a0fb16ba5b372465a3a1ecd761c6fa911a4ab4d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a226e5b49e5fe8c98b14f8507de670189d191348",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a36cf138500e56f50db9f9a33222df6969b38326",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a8aec14230322ed8f1e8042b6d656c1631d41163",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e48bf8f1d2b12c1c5ba1f609edbd4cde5dadc20e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm/bus: Fix potential use after free in asynchronous initialization\n\nDingisoul with KASAN reports a use after free if device_add() fails in\nnd_async_device_register().\n\nCommit b6eae0f61db2 (\"libnvdimm: Hold reference on parent while\nscheduling async init\") correctly added a reference on the parent device\nto be held until asynchronous initialization was complete.  However, if\ndevice_add() results in an allocation failure the ref count of the\ndevice drops to 0 prior to the parent pointer being accessed.  Thus\nresulting in use after free.\n\nThe bug bot AI correctly identified the fix.  Save a reference to the\nparent pointer to be used to drop the parent reference regardless of the\noutcome of device_add()."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnvdimm/bus: Soluciona un posible uso después de liberar en la inicialización asíncrona\n\nDingisoul con KASAN informa de un uso después de liberar si device_add() falla en nd_async_device_register().\n\nEl commit b6eae0f61db2 ('libnvdimm: Mantener referencia en el padre mientras se programa la inicialización asíncrona') añadió correctamente una referencia en el dispositivo padre para ser mantenida hasta que la inicialización asíncrona estuviera completa. Sin embargo, si device_add() resulta en un fallo de asignación, el contador de referencias del dispositivo cae a 0 antes de que se acceda al puntero padre. Resultando así en un uso después de liberar.\n\nLa IA del bot de errores identificó correctamente la solución. Guarda una referencia al puntero padre para ser utilizada para liberar la referencia padre independientemente del resultado de device_add()."
    }
  ],
  "lastModified": "2026-07-24T22:10:00.140",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F465C16-7558-45C0-8A57-E91446282ED2",
              "versionEndExcluding": "4.5",
              "versionStartIncluding": "4.4.164"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37605FCB-BF78-48D6-8838-00E69121C271",
              "versionEndExcluding": "4.10",
              "versionStartIncluding": "4.9.137"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E3D2C10-16F9-4F31-94C6-EBE99C89FF70",
              "versionEndExcluding": "4.15",
              "versionStartIncluding": "4.14.81"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D418973-A1B7-4F79-B990-AFFA8B41983C",
              "versionEndExcluding": "4.19",
              "versionStartIncluding": "4.18.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38D904CC-7C9A-4A9A-9A82-96FD6C821BB3",
              "versionEndExcluding": "5.10.253",
              "versionStartIncluding": "4.19.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20DDB3E9-AABF-4107-ADB0-5362AA067045",
              "versionEndExcluding": "5.15.203",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EDC6BAF-B710-4E26-B6AA-D68922EE7B43",
              "versionEndExcluding": "6.1.167",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C57BB918-DF28-46B3-94F7-144176841267",
              "versionEndExcluding": "6.6.130",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28D591F5-B196-4CC9-905C-DC80F116E7A8",
              "versionEndExcluding": "6.12.78",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5571059-6552-48E7-9BEF-3E358C387171",
              "versionEndExcluding": "6.18.20",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96D34333-38BE-4414-9E79-6EB764329581",
              "versionEndExcluding": "6.19.10",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}