CVE-2026-31565
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-31565 is a deadlock vulnerability in the Linux kernel's RDMA/irdma driver that causes system hangs when a network device reset is performed while RDMA applications (e.g., rping) are active. The flaw was published on April 24, 2026, and affects multiple Linux kernel stable branches, including versions from 5.15.116 through 5.15.202, 6.1.33 through 6.1.167, 6.4.1 through 6.6.130, 6.7 through 6.12.79, 6.13 through 6.18.20, and 6.19 through 6.19.10, as well as kernel 7.0 release candidates (Red Hat CVE, Feedly). It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).

Technical details

The root cause involves two related weaknesses: improper update of reference count (CWE-911) and improper locking (CWE-667). When a netdev reset is triggered, the ice driver removes the irdma auxiliary driver, initiating device deletion and client removal. During this process, uverbs_client waits indefinitely for the Queue Pair (QP) reference count to reach zero, while cma_client holds the final reference — creating a circular dependency and deadlock in iWARP mode. The fix skips the QP reference count wait during device reset to break the circular dependency (Feedly, Red Hat CVE).

Impact

Successful triggering of this vulnerability causes the system to hang indefinitely, resulting in a complete loss of availability for the affected host. Services dependent on the RDMA/irdma driver become unresponsive, and the system cannot recover without manual intervention or a full restart. There is no confidentiality or integrity impact; the vulnerability is purely an availability issue, but it is particularly severe in high-performance computing and data center environments where RDMA is used for latency-sensitive workloads (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report (Feedly). The vulnerability requires local access with low privileges (a local user able to trigger a netdev reset while RDMA applications are running), limiting its attack surface. The EPSS score is approximately 0.024% (0.000240), indicating a very low probability of exploitation in the near term (Feedly). The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.

Mitigation and workarounds

Apply the patched Linux kernel versions as soon as possible: 5.15.203 or later (5.15.x branch), 6.1.168 or later (6.1.x branch), 6.6.131 or later (6.6.x branch), 6.12.80 or later (6.12.x branch), 6.18.21 or later (6.18.x branch), 6.19.11 or later (6.19.x branch), or kernel 7.0 final release. SUSE has released security advisories (SUSE-SU-202621834-1, SUSE-SU-20262217-1, SUSE-SU-20262238-1) addressing this issue (Feedly). As a temporary workaround, avoid performing netdev reset operations while RDMA applications are actively running, or disable RDMA drivers if they are not required in production (Feedly).

Community reactions

Red Hat has acknowledged the vulnerability and published a CVE advisory page, rating it as Medium severity (Red Hat CVE). SUSE issued multiple security update announcements addressing the flaw across their supported kernel branches (Feedly). The Yocto Project security mailing list also flagged the issue for embedded Linux maintainers (Feedly). No notable independent researcher commentary or significant social media discussion has been observed.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management