VDB

DEBIAN-CVE-2026-31574

DEBIAN-CVE-2026-31574 REJECTED CVSS 9.300000190734863 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: clockevents: Add missing resets of the next_event_forced flag The prevention mechanism against timer interrupt starvation missed to reset the next_event_forced flag in a couple of places: - When the clock event state changes. That can cause the flag to be stale over a shutdown/startup sequence - When a non-forced event is armed, which then prevents rearming before that event. If that event is far out in the future this will cause missed timer interrupts. - In the suspend wakeup handler. That led to stalls which have been reported by several people. Add the missing resets, which fixes the problems for the reporters.

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:13linux0, 7.0.1-1, 7.0-1
Debian:14linux0, 6.12.38-1, 6.12.41-1
Debian:11linux7.0.1-1, 6.18.15-1~bpo13+1, 6.18.2-1~exp1
Debian:12linux6.6.15-1, 6.6.15-2, 6.6.3-1~exp1

Timeline

  • Apr 27, 2026 CVE Rejected
Open in Interactive Console →
$ Console Community · 100/wk Open console ›