CVE-2026-31781: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/ioc32: stop speculation on the drm_compat_ioctl path The drm compat ioctl path takes a user controlled pointer, and then dereferences it into a table of function pointers, the signature method of spectre problems. Fix this up by calling array_index_nospec() on the index to the function pointer list.

Affected products

  • Linux Linux Kernel: from 3.16.63, before 3.17 (fixed in 3.17); from 4.4.170, before 4.5 (fixed in 4.5); from 4.9.148, before 4.10 (fixed in 4.10); from 4.14.91, before 4.15 (fixed in 4.15); from 4.19.13, before 4.20 (fixed in 4.20); from 4.20.1, before 5.10.253 (fixed in 5.10.253); …

Published 2026-05-01. Last modified 2026-06-17.