CVE-2026-31559: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing NULL checks for kstrdup() 1. Replace "of_find_node_by_path("/")" with "of_root" to avoid multiple calls to "of_node_put()". 2. Fix a potential kernel oops during early boot when memory allocation fails while parsing CPU model from device tree.
Affected products
- Linux Linux Kernel: from 6.12.43, before 6.12.80 (fixed in 6.12.80); from 6.15.11, before 6.16 (fixed in 6.16); from 6.16.2, before 6.17 (fixed in 6.17); from 6.17.1, before 6.18.21 (fixed in 6.18.21); from 6.19, before 6.19.11 (fixed in 6.19.11); version 6.17 only; …
Published 2026-04-24. Last modified 2026-06-17.