CVE-2026-31595
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/04/2026
Last modified:
29/04/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup<br />
<br />
Disable the delayed work before clearing BAR mappings and doorbells to<br />
avoid running the handler after resources have been torn down.<br />
<br />
Unable to handle kernel paging request at virtual address ffff800083f46004<br />
[...]<br />
Internal error: Oops: 0000000096000007 [#1] SMP<br />
[...]<br />
Call trace:<br />
epf_ntb_cmd_handler+0x54/0x200 [pci_epf_vntb] (P)<br />
process_one_work+0x154/0x3b0<br />
worker_thread+0x2c8/0x400<br />
kthread+0x148/0x210<br />
ret_from_fork+0x10/0x20
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.0 (including) | 6.6.136 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.83 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.0 (including) | 7.0.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/5999067140c67530a6cb6f41a8471596e60452cb
- https://git.kernel.org/stable/c/6773cc24c004930903a57761132c1e7728907f8f
- https://git.kernel.org/stable/c/9921cce25bfe4021f6e55ca995351eb967165297
- https://git.kernel.org/stable/c/ceb73484e7204f661f770069ecdf35f6e941879c
- https://git.kernel.org/stable/c/d799984233a50abd2667a7d17a9a710a3f10ebe2
- https://git.kernel.org/stable/c/fbb6c353fa2fb5f5f990eda034a1074b0356127e



