CVE-2026-31782: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Fix potential bad container_of in intel_pmu_hw_config Auto counter reload may have a group of events with software events present within it. The software event PMU isn't the x86_hybrid_pmu and a container_of operation in intel_pmu_set_acr_caused_constr (via the hybrid helper) could cause out of bound memory reads. Avoid this by guarding the call to intel_pmu_set_acr_caused_constr with an is_x86_event check.

Affected products

  • Linux Linux Kernel: from 6.16.1, before 6.18.22 (fixed in 6.18.22); from 6.19, before 6.19.12 (fixed in 6.19.12); version 6.16 only; version 7.0 only

Published 2026-05-01. Last modified 2026-06-17.