VDB
CVE-2026-31527
CVE-2026-31527
PUBLISHED
In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]
EPSS 0.02% · 3.5th percentile
Risk Scores
EPSS Score
0.02%
3.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linux | linux_kernel | 3.17, 3.17, 3.17 |
| Linux | Linux | 3d713e0e382e6fcfb4bba1501645b66c129ad60b, 3d713e0e382e6fcfb4bba1501645b66c129ad60b, 3d713e0e382e6fcfb4bba1501645b66c129ad60b |
Timeline
- Apr 22, 2026 CVE Published
- Apr 23, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
References
- https://git.kernel.org/stable/c/9a6086d2a828dd2ff74cf9abcae456670febd71f url
- https://git.kernel.org/stable/c/7c02a9bd7d14a89065fcf672b86d8e1d1a41d3b1 url
- https://git.kernel.org/stable/c/edee7ee5a14c3b33f6d54641f5af5c5e9180992d url
- https://git.kernel.org/stable/c/2b38efc05bf7a8568ec74bfffea0f5cfa62bc01d url
- https://nvd.nist.gov/vuln/detail/CVE-2026-31527 advisory
- https://lists.debian.org/debian-security-announce/2026/msg00154.html advisory
- https://lists.debian.org/debian-security-announce/2026/msg00148.html advisory