CVE-2026-31645: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix page pool leak in error paths lan966x_fdma_rx_alloc() creates a page pool but does not destroy it if the subsequent fdma_alloc_coherent() call fails, leaking the pool. Similarly, lan966x_fdma_init() frees the coherent DMA memory when lan966x_fdma_tx_alloc() fails but does not destroy the page pool that was successfully created by lan966x_fdma_rx_alloc(), leaking it. Add the missing page_pool_destroy() calls in both error paths.

Affected products

  • Linux Linux Kernel: from 6.2.1, before 6.12.82 (fixed in 6.12.82); from 6.13, before 6.18.23 (fixed in 6.18.23); from 6.19, before 6.19.13 (fixed in 6.19.13); version 6.2 only; version 7.0 only

Published 2026-04-24. Last modified 2026-06-17.