
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31735 is a Linux kernel vulnerability in the IOMMU page table (iommupt) subsystem, specifically a short TLB gather/invalidation bug when an unmap operation lands within a large or contiguous IOPTE (IO Page Table Entry). The flaw causes the gather operation to flush only the explicitly requested unmap range rather than the full range actually unmapped, resulting in incomplete TLB invalidation. It affects Linux kernel versions 6.19 through 6.19.11 and 7.0 release candidates rc1 through rc6. It was published on May 1, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-459 (Incomplete Cleanup): when iommu_unmap() unmaps a range whose endpoint falls within a large or contiguous IOPTE, the kernel unmaps more memory than requested but the associated TLB gather structure is only updated for the originally requested range. This leaves stale TLB entries for the additional unmapped region, bypassing the intended invalidation. The bug was discovered through a new invalidation/gather test being developed in preparation for ARMv8 support, and the root cause was identified with the assistance of AI analysis. The kernel maintainers note that no existing code path is known to rely on unmapping a large entry in this way, making the bug "likely not a triggerable" condition in practice (Red Hat Bugzilla, Red Hat Advisory).
A local user with low privileges could potentially trigger an unmap operation that lands in the middle of a large IOPTE, leaving stale TLB mappings that allow unauthorized read or write access to memory regions that should have been invalidated. The CVSS scope is marked as Changed, indicating that the impact can extend beyond the vulnerable component itself — potentially affecting memory isolation enforced by the IOMMU, which is critical for device isolation and virtualization security. Confidentiality, integrity, and availability are all rated High in the CVSS vector, reflecting the theoretical potential for memory disclosure and corruption (Red Hat Advisory, Red Hat Bugzilla).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The kernel maintainers themselves note the bug is "likely not a triggerable" condition under normal usage. The EPSS score is extremely low at 0.018%, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory).
Patches are available in the Linux kernel stable repositories. Affected users should upgrade to Linux kernel version 6.19.12 or later, or the final 7.0 release. The fixes are referenced in the kernel stable git repository at commits 50ecd96a28f7 and ee6e69d03255. No configuration-based workaround has been published; patching is the recommended remediation (Red Hat Bugzilla, Kernel Patch 1, Kernel Patch 2).
Fix availability across major Linux distributions and their releases.
bionic
linux
bionic (esm-infra)
linux
bionic (fips-updates)
linux-fips
bionic (fips)
linux-fips
devel
linux
focal
linux
focal (esm-infra)
linux
focal (fips-updates)
linux-fips
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."