Review reviewHigh

CVE-2026-31399

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingisoul with KASAN reports a use after free if device_add() fails in nd_async_device_register(). Commit b6eae0f61db2 ("libnvdimm: Hold reference on parent while scheduling async init") correctly added a reference on the parent device to be held until asynchronous initialization was complete. However, if device_add() results in an allocation failure the ref count of the device drops to 0 prior to the parent pointer being accessed. Thus resulting in use...

CVSS
7.8
EPSS
0.12%
2.10% percentile
CISA KEV
Not listed
Published
2026.04.04
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.12%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingisoul with KASAN reports a use after free if device_add() fails in nd_async_device_register(). Commit b6eae0f61db2 ("libnvdimm: Hold reference on parent while scheduling async init") correctly added a reference on the parent device to be held until asynchronous initialization was complete. However, if device_add() results in an allocation failure the ref count of the device drops to 0 prior to the parent pointer being accessed. Thus resulting in use...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < 6fc36c2a925ceaba203eb13d75a8f0879a2c121b, >= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < a36cf138500e56f50db9f9a33222df6969b38326, >= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < 9a0fb16ba5b372465a3a1ecd761c6fa911a4ab4d, >= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < e48bf8f1d2b12c1c5ba1f609edbd4cde5dadc20e, >= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < 2c638259ad750833fd46a0cf57672a618542d84c, >= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < a226e5b49e5fe8c98b14f8507de670189d191348, >= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < 84af19855d1abdee3c9d57c0684e2868e391793c, >= b6eae0f61db27748606cc00dafcfd1e2c032f0a5 < a8aec14230322ed8f1e8042b6d656c1631d41163, >= 8954771abdea5c34280870e35592c7226a816d95, >= 3e63a7f25cc85d3d3e174b9b0e3489ebb7eaf4ab, >= 1490de2bb0836fc0631c04d0559fdf81545b672f, >= e31a8418c8df7e6771414f99ed3d95ba8aca4e05, >= 4f1a55a4f990016406147cf3e0c9487bf83e50f0, >= 4.4.164 < 4.5, >= 4.9.137 < 4.10, >= 4.14.81 < 4.15, >= 4.18.19 < 4.19, >= 4.19.2 < 4.20, >= 4.20, >= 4.19.2 < 5.10.253
Fixed versions
4.5, 4.10, 4.15, 4.19, 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416