CVE-2026-31558

medium Red Hat
EPSS Score
0.0%
Exploitation probability in 30 days
Top 95% most likely to be exploited
Published: April 24, 2026 (20 days ago)
Last Modified: April 24, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component. A local attacker could potentially trigger an out-of-bounds memory access by providing a negative 'cpuid' parameter to the 'kvm_get_vcpu_by_cpuid()' function. This could lead to system instability or potentially other impacts due to memory corruption.

CWE

CWE-839

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References