PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup
Summary
| CVE | CVE-2026-31595 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-24 15:16:37 UTC |
| Updated | 2026-06-01 17:16:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup Disable the delayed work before clearing BAR mappings and doorbells to avoid running the handler after resources have been torn down. Unable to handle kernel paging request at virtual address ffff800083f46004 [...] Internal error: Oops: 0000000096000007 [#1] SMP [...] Call trace: epf_ntb_cmd_handler+0x54/0x200 [pci_epf_vntb] (P) process_one_work+0x154/0x3b0 worker_thread+0x2c8/0x400 kthread+0x148/0x210 ret_from_fork+0x10/0x20 |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.000180000 probability, percentile 0.048130000 (date 2026-04-27)
Problem Types: NVD-CWE-noinfo
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected e35f56bb03304abc92c928b641af41ca372966bb b2eb405bbced3a6e772545e1b74dbde37cee1f8f git | Not specified |
| CNA | Linux | Linux | affected e35f56bb03304abc92c928b641af41ca372966bb ceb73484e7204f661f770069ecdf35f6e941879c git | Not specified |
| CNA | Linux | Linux | affected e35f56bb03304abc92c928b641af41ca372966bb 6773cc24c004930903a57761132c1e7728907f8f git | Not specified |
| CNA | Linux | Linux | affected e35f56bb03304abc92c928b641af41ca372966bb 9921cce25bfe4021f6e55ca995351eb967165297 git | Not specified |
| CNA | Linux | Linux | affected e35f56bb03304abc92c928b641af41ca372966bb 5999067140c67530a6cb6f41a8471596e60452cb git | Not specified |
| CNA | Linux | Linux | affected e35f56bb03304abc92c928b641af41ca372966bb fbb6c353fa2fb5f5f990eda034a1074b0356127e git | Not specified |
| CNA | Linux | Linux | affected e35f56bb03304abc92c928b641af41ca372966bb d799984233a50abd2667a7d17a9a710a3f10ebe2 git | Not specified |
| CNA | Linux | Linux | affected e2b6ef72b7aea9d7d480d2df499bcd1c93247abb git | Not specified |
| CNA | Linux | Linux | affected 5.15.153 5.16 semver | Not specified |
| CNA | Linux | Linux | affected 6.0 | Not specified |
| CNA | Linux | Linux | unaffected 6.0 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.175 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.136 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.83 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.24 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.19.14 6.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.1 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/5999067140c67530a6cb6f41a8471596e60452cb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/b2eb405bbced3a6e772545e1b74dbde37cee1f8f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ceb73484e7204f661f770069ecdf35f6e941879c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/9921cce25bfe4021f6e55ca995351eb967165297 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/fbb6c353fa2fb5f5f990eda034a1074b0356127e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/d799984233a50abd2667a7d17a9a710a3f10ebe2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/6773cc24c004930903a57761132c1e7728907f8f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.