Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-31552

7.5 · HIGH
Published Apr 24, 2026 linux CWE-835

Overview

CVE-2026-31552 is a high-severity vulnerability affecting linux linux_kernel. It was published on April 24, 2026 and has a CVSS 3.1 base score of 7.5 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom

Since upstream commit e75665dd0968 ("wifi: wlcore: ensure skb headroom

before skb_push"), wl1271_tx_allocate() and with it

wl1271_prepare_tx_frame() returns -EAGAIN if pskb_expand_head() fails.

However, in wlcore_tx_work_locked(), a return value of -EAGAIN from

wl1271_prepare_tx_frame() is interpreted as the aggregation buffer being

full. This causes the code to flush the buffer, put the skb back at the

head of the queue, and immediately retry the same skb in a tight while

loop.

Because wlcore_tx_work_locked() holds wl->mutex, and the retry happens

immediately with GFP_ATOMIC, this will result in an infinite loop and a

CPU soft lockup. Return -ENOMEM instead so the packet is dropped and

the loop terminates.

The problem was found by an experimental code review agent based on

gemini-3.1-pro while reviewing backports into v6.18.y.

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.10.250, < 5.10.253 Affected

Frequently Asked Questions

What is CVE-2026-31552?

CVE-2026-31552 is a high-severity vulnerability affecting linux linux_kernel. It was published on April 24, 2026 and has a CVSS 3.1 base score of 7.5 (HIGH).

How severe is CVE-2026-31552?

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2026-31552?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-31552?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-31552 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.