CVE-2026-31482: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: s390/entry: Scrub r12 register on kernel entry Before commit f33f2d4c7c80 ("s390/bp: remove TIF_ISOLATE_BP"), all entry handlers loaded r12 with the current task pointer (lg %r12,__LC_CURRENT) for use by the BPENTER/BPEXIT macros. That commit removed TIF_ISOLATE_BP, dropping both the branch prediction macros and the r12 load, but did not add r12 to the register clearing sequence. Add the missing xgr %r12,%r12 to make the register scrub consistent across all entry points.
Affected products
- Linux Linux Kernel: from 6.4.1, before 6.6.131 (fixed in 6.6.131); from 6.7, before 6.12.80 (fixed in 6.12.80); from 6.13, before 6.18.21 (fixed in 6.18.21); from 6.19, before 6.19.11 (fixed in 6.19.11); version 6.4 only; version 7.0 only
Published 2026-04-22. Last modified 2026-06-17.