CVE-2026-31651: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix NULL-deref on disconnect Make sure to deregister the controller before dropping the reference to the driver data on disconnect to avoid NULL-pointer dereferences or use-after-free.

Affected products

  • Linux Linux Kernel: from 3.0.1, before 5.10.253 (fixed in 5.10.253); from 5.11, before 5.15.203 (fixed in 5.15.203); from 5.16, before 6.1.169 (fixed in 6.1.169); from 6.2, before 6.6.135 (fixed in 6.6.135); from 6.7, before 6.12.82 (fixed in 6.12.82); from 6.13, before 6.18.23 (fixed in 6.18.23); …

Published 2026-04-24. Last modified 2026-07-14.