CVE-2026-31545
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-31545 is a vulnerability in the Linux kernel's NFC nxp-nci driver caused by an improper GPIO sleep constraint that prevents firmware and enable GPIOs from sleeping. This flaw breaks driver operation when GPIOs are connected to I2C GPIO expanders and triggers a kernel WARN_ON in drivers/gpio/gpiolib.c. Affected Linux kernel versions span multiple stable branches: 5.4–5.10 (before 5.10.253), 5.11–5.15 (before 5.15.203), 5.16–6.1 (before 6.1.167), 6.2–6.6 (before 6.6.130), 6.7–6.12 (before 6.12.78), 6.13–6.18 (before 6.18.20), 6.19 (before 6.19.10), and 7.0-rc1 through rc4. It was published on April 24, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).

Technical details

The root cause is classified as CWE-372 (Incomplete Internal State Distinction): the nxp-nci NFC driver uses gpiod_set_value() instead of gpiod_set_value_cansleep() for firmware and enable GPIO lines, which does not account for GPIOs that may need to sleep (e.g., those routed through I2C GPIO expanders). When such a GPIO is accessed, the kernel's GPIO library (gpiolib.c, line 3880) fires a WARN_ON assertion because the calling context does not permit sleeping. The fix allows the GPIOs to sleep by switching to the appropriate sleep-capable GPIO API calls, enabling correct operation with I2C-connected GPIO expanders (Red Hat CVE, Kernel Patch).

Impact

The primary impact is an availability loss affecting NFC functionality on systems where the nxp-nci driver controls GPIOs via I2C GPIO expanders. Exploitation results in a kernel WARNING at gpiod_set_value+0x88/0x98 and driver malfunction, rendering NFC hardware inoperable. There is no confidentiality or integrity impact; the vulnerability is limited to local availability of the NFC subsystem (Feedly, Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The vulnerability requires local access (low-privileged user) and is only triggerable on systems with NFC hardware using the nxp-nci driver connected to I2C GPIO expanders. The EPSS score is approximately 0.024% (0.000240), indicating very low likelihood of exploitation. CVE-2026-31545 is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).

Indicators of compromise

  • Logs: Kernel log entries containing WARNING: CPU: X PID: XXXX at drivers/gpio/gpiolib.c:3880 gpiod_set_value+0x88/0x98, indicating the WARN_ON has been triggered in the GPIO library.
  • Process: Unexpected NFC driver failures or NFC device becoming unresponsive, particularly on systems with I2C GPIO expanders.
  • System: Repeated kernel warnings in dmesg or /var/log/kern.log referencing the nxp-nci driver and GPIO operations.

Mitigation and workarounds

Update the Linux kernel to a patched version for the applicable stable branch: 5.10.253+ (5.4–5.10), 5.15.203+ (5.11–5.15), 6.1.167+ (5.16–6.1), 6.6.130+ (6.2–6.6), 6.12.78+ (6.7–6.12), 6.18.20+ (6.13–6.18), 6.19.10+ (6.19), or Linux 7.0 and later. Patches are available via the upstream kernel stable tree. Systems without NFC hardware or not using I2C GPIO expanders are not affected and have lower urgency, though updating is still recommended (Red Hat CVE, Kernel Patch).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.170-1

Fixed

sid

linux: 6.19.10-1

Fixed

trixie

linux: 6.12.85-1

Fixed

Ubuntu

Fixed

bionic

linux

Not Affected

bionic (esm-infra)

linux-hwe-5.4

Affected

bionic (fips-updates)

linux-fips

Not Affected

bionic (fips)

linux-fips

Not Affected

devel

linux

Not Affected

focal

linux-azure-fde-5.15

Not Affected

focal (esm-infra)

linux

Affected

focal (fips-updates)

linux-fips

Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80904MEDIUM5.9
  • Linux Kernel logoLinux Kernel
  • linux-aws-6.14
NoYesSep 04, 2026
CVE-2026-80905MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-gkeop
NoYesSep 04, 2026
CVE-2026-80913MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-ibm-5.4
NoYesSep 04, 2026
CVE-2026-80912MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-oem-6.14
NoYesSep 04, 2026
CVE-2026-80906NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-nvidia-6.14
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management