CVE-2026-31501

medium Red Hat
Published: April 22, 2026 (22 days ago)
Last Modified: April 22, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's `net: ti: icssg-prueth` driver. This use-after-free vulnerability occurs in the receive (RX) path, where a data structure (CPPI descriptor) is released from memory before all necessary operations on its contents are complete. A remote attacker could exploit this by sending specially crafted network packets, potentially leading to memory corruption and system instability or denial of service.

CWE

CWE-825

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References