VDB

CVE-2026-31781

CVE-2026-31781 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: drm/ioc32: stop speculation on the drm_compat_ioctl path The drm compat ioctl path takes a user controlled pointer, and then dereferences it into a table of function pointers, the signature method of spectre problems. Fix this up by calling array_index_nospec() on the index to the function pointer list.

EPSS 0.02% · 3.4th percentile

Risk Scores

EPSS Score
0.02%
3.4th percentile

Affected Products

VendorProductVersions
linuxlinux_kernel4.20, 4.20, 4.20
LinuxLinux505b5240329b922f21f91d5b5d1e535c805eca6d, 505b5240329b922f21f91d5b5d1e535c805eca6d, 505b5240329b922f21f91d5b5d1e535c805eca6d

Timeline

  • May 1, 2026 CVE Published
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 23, 2026 CVE Updated
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›