CVE-2026-31529

MEDIUM

cxl/region: Fix leakage in __construct_region()

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __construct_region() Failing the first sysfs_update_group() needs to explicitly kfree the resource as it is too early for cxl_region_iomem_release() to do so.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (8)
Linux/Linux < 6.19
Linux/Linux 6.19
Linux/Linux 6.19.11 - 6.19.*
Linux/Linux 7.0
Linux/Linux d6602e25819dea2c239972e98e09ba5db4aebd22 - 77b310bb7b5ff8c017524df83292e0242ba89791
Linux/Linux d6602e25819dea2c239972e98e09ba5db4aebd22 - f1b4741adf08b0063291ec1b0dfa9c3d55644933
linux/linux_kernel 7.0 rc1 (5 CPE variants)
linux/linux_kernel 6.19 - 6.19.11
Published Apr 22, 2026
Tracked Since Apr 22, 2026