CVE-2026-31735
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-31735 is a Linux kernel vulnerability in the IOMMU page table (iommupt) subsystem, specifically a short TLB gather/invalidation bug when an unmap operation lands within a large or contiguous IOPTE (IO Page Table Entry). The flaw causes the gather operation to flush only the explicitly requested unmap range rather than the full range actually unmapped, resulting in incomplete TLB invalidation. It affects Linux kernel versions 6.19 through 6.19.11 and 7.0 release candidates rc1 through rc6. It was published on May 1, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-459 (Incomplete Cleanup): when iommu_unmap() unmaps a range whose endpoint falls within a large or contiguous IOPTE, the kernel unmaps more memory than requested but the associated TLB gather structure is only updated for the originally requested range. This leaves stale TLB entries for the additional unmapped region, bypassing the intended invalidation. The bug was discovered through a new invalidation/gather test being developed in preparation for ARMv8 support, and the root cause was identified with the assistance of AI analysis. The kernel maintainers note that no existing code path is known to rely on unmapping a large entry in this way, making the bug "likely not a triggerable" condition in practice (Red Hat Bugzilla, Red Hat Advisory).

Impact

A local user with low privileges could potentially trigger an unmap operation that lands in the middle of a large IOPTE, leaving stale TLB mappings that allow unauthorized read or write access to memory regions that should have been invalidated. The CVSS scope is marked as Changed, indicating that the impact can extend beyond the vulnerable component itself — potentially affecting memory isolation enforced by the IOMMU, which is critical for device isolation and virtualization security. Confidentiality, integrity, and availability are all rated High in the CVSS vector, reflecting the theoretical potential for memory disclosure and corruption (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The kernel maintainers themselves note the bug is "likely not a triggerable" condition under normal usage. The EPSS score is extremely low at 0.018%, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory).

Mitigation and workarounds

Patches are available in the Linux kernel stable repositories. Affected users should upgrade to Linux kernel version 6.19.12 or later, or the final 7.0 release. The fixes are referenced in the kernel stable git repository at commits 50ecd96a28f7 and ee6e69d03255. No configuration-based workaround has been published; patching is the recommended remediation (Red Hat Bugzilla, Kernel Patch 1, Kernel Patch 2).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Fixed

sid

linux: 6.19.12-1

Fixed

trixie

linux

Fixed

Ubuntu

Fixed

bionic

linux

Not Affected

bionic (esm-infra)

linux

Not Affected

bionic (fips-updates)

linux-fips

Not Affected

bionic (fips)

linux-fips

Not Affected

devel

linux

Not Affected

focal

linux

Not Affected

focal (esm-infra)

linux

Not Affected

focal (fips-updates)

linux-fips

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80904MEDIUM5.9
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 04, 2026
CVE-2026-80905MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 04, 2026
CVE-2026-80913MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux
NoYesSep 04, 2026
CVE-2026-80912MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-azure
NoYesSep 04, 2026
CVE-2026-80906NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-hwe-7.0
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management