Review reviewHigh

CVE-2026-31703

Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6

In the Linux kernel, the following vulnerability has been resolved: writeback: Fix use after free in inode_switch_wbs_work_fn() inode_switch_wbs_work_fn() has a loop like: wb_get(new_wb); while (1) { list = llist_del_all(&new_wb->switch_wbs_ctxs); /* Nothing to do? */ if (!list) break; ... process the items ... } Now adding of items to the list looks like: wb_queue_isw() if (llist_add(&isw->list, &wb->switch_wbs_ctxs)) queue_work(isw_wq, &wb->switch_work); Because inode_switch_wbs_work_fn() loops when processing isw items, it can happen that wb->switch_work is pending while wb->switch_wbs_c...

CVSS
7.8
EPSS
0.12%
2.06% percentile
CISA KEV
Not listed
Published
2026.05.01
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.12%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: writeback: Fix use after free in inode_switch_wbs_work_fn() inode_switch_wbs_work_fn() has a loop like: wb_get(new_wb); while (1) { list = llist_del_all(&new_wb->switch_wbs_ctxs); /* Nothing to do? */ if (!list) break; ... process the items ... } Now adding of items to the list looks like: wb_queue_isw() if (llist_add(&isw->list, &wb->switch_wbs_ctxs)) queue_work(isw_wq, &wb->switch_work); Because inode_switch_wbs_work_fn() loops when processing isw items, it can happen that wb->switch_work is pending while wb->switch_wbs_c...

Affected product and versions

Product
Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6
Affected versions
>= d072b38a64ddbc2d58c2e525a24af24ecbfebcb7 < 382cf81cae89e58d22b4bdc38891cd4d0b9ba921, >= ac7b2c21f2269d815ad0cdf0f8258d55185b805c < 19ec404b079be057b387643ba0c69bbcc5867c35, >= fabfc1fcddc5d8185722d4fde5f0968c4760b71e < 156cc63691c1f20905510b1007896e090355e6c2, >= e1b849cfa6b61f1c866a908c9e8dd9b5aaab820b < 028103656b84273c73e9e271cf95c9f3421f4b8a, >= e1b849cfa6b61f1c866a908c9e8dd9b5aaab820b < 9223e5f30403a9b506d6d0bff4f2e29a2d7d46af, >= e1b849cfa6b61f1c866a908c9e8dd9b5aaab820b < 6689f01d6740cf358932b3e97ee968c6099800d9, >= 6.18, >= 6.18 < 6.18.25, >= 6.19 < 7.0.2, 7.1
Fixed versions
6.18.25, 7.0.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416, CWE-825
CVE-2026-31703 — Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6 | SECUFOCUS NOW