CVE-2026-31687: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Commit 11a78b794496 ("ARM: OMAP: MPUIO wake updates") registers the omap_mpuio_driver from omap_mpuio_init(), which is called from omap_gpio_probe(). However, it neither makes sense to register drivers from probe() callbacks of other drivers, nor does the driver core allow registering drivers with a device lock already being held. The latter was revealed by commit dc23806a7c47 ("driver core: enforce device_lock for driver_match_device()") leading to a potential deadlock condition described in [1]. Additionally, the omap_mpuio_driver is never unregistered from the driver core, even if the module is unloaded. Hence, register the omap_mpuio_driver from the module initcall and unregister it in module_exit().
Affected products
- Linux Linux Kernel: from 2.6.22, before 5.10.251 (fixed in 5.10.251); from 5.11, before 5.15.201 (fixed in 5.15.201); from 5.16, before 6.1.164 (fixed in 6.1.164); from 6.2, before 6.6.125 (fixed in 6.6.125); from 6.7, before 6.12.72 (fixed in 6.12.72); from 6.13, before 6.18.11 (fixed in 6.18.11); …
Published 2026-04-27. Last modified 2026-06-17.