CVE-2026-31730 (GCVE-0-2026-31730)
Vulnerability from cvelistv5
Published
2026-05-01 14:14
Modified
2026-08-05 12:24
Summary
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: possible double-free of cctx->remote_heap fastrpc_init_create_static_process() may free cctx->remote_heap on the err_map path but does not clear the pointer. Later, fastrpc_rpmsg_remove() frees cctx->remote_heap again if it is non-NULL, which can lead to a double-free if the INIT_CREATE_STATIC ioctl hits the error path and the rpmsg device is subsequently removed/unbound. Clear cctx->remote_heap after freeing it in the error path to prevent the later cleanup from freeing it again. This issue was found by an in-house analysis workflow that extracts AST-based information and runs static checks, with LLM assistance for triage, and was confirmed by manual code review. No hardware testing was performed.
Impacted products
Vendor Product Version
Linux Linux Version: 0871561055e666da421d779397efcc1e5e964cab
Version: 0871561055e666da421d779397efcc1e5e964cab
Version: 0871561055e666da421d779397efcc1e5e964cab
Version: 0871561055e666da421d779397efcc1e5e964cab
Version: 0871561055e666da421d779397efcc1e5e964cab
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/misc/fastrpc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4b8e527aca357a6488680713bd88007cf8f547fe",
              "status": "affected",
              "version": "0871561055e666da421d779397efcc1e5e964cab",
              "versionType": "git"
            },
            {
              "lessThan": "0bdee4118340c5a756220c1b29a7dab86bb0aa65",
              "status": "affected",
              "version": "0871561055e666da421d779397efcc1e5e964cab",
              "versionType": "git"
            },
            {
              "lessThan": "3a164f640953cc982804746e772d379171aff5c6",
              "status": "affected",
              "version": "0871561055e666da421d779397efcc1e5e964cab",
              "versionType": "git"
            },
            {
              "lessThan": "f67d368d26764a357691b2b3a33d3cb55b435bfc",
              "status": "affected",
              "version": "0871561055e666da421d779397efcc1e5e964cab",
              "versionType": "git"
            },
            {
              "lessThan": "ba2c83167b215da30fa2aae56b140198cf8d8408",
              "status": "affected",
              "version": "0871561055e666da421d779397efcc1e5e964cab",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/misc/fastrpc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.134",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.81",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.22",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.134",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.81",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.22",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.12",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: possible double-free of cctx-\u003eremote_heap\n\nfastrpc_init_create_static_process() may free cctx-\u003eremote_heap on the\nerr_map path but does not clear the pointer. Later, fastrpc_rpmsg_remove()\nfrees cctx-\u003eremote_heap again if it is non-NULL, which can lead to a\ndouble-free if the INIT_CREATE_STATIC ioctl hits the error path and the rpmsg\ndevice is subsequently removed/unbound.\nClear cctx-\u003eremote_heap after freeing it in the error path to prevent the\nlater cleanup from freeing it again.\n\nThis issue was found by an in-house analysis workflow that extracts AST-based\ninformation and runs static checks, with LLM assistance for triage, and was\nconfirmed by manual code review.\nNo hardware testing was performed."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - FastRPC is reached by a local process opening the fastrpc misc device and issuing FASTRPC_IOCTL_INIT_CREATE_STATIC through the ioctl path. There is no network, adjacent, or physical packet path to this driver entry point.\nAC:L - No race is required; the attacker controls the ioctl arguments and can drive the error path that frees cctx-\u003eremote_heap while leaving the stale pointer in the vulnerable code. The stale pointer can then be reached again by retrying the ioctl or during rpmsg teardown, so exploitation does not depend on conditions outside the attacker\u0027s practical control.\nPR:L - The driver path has no capable() or namespace privilege check; access is gated only by the fastrpc device node. In reasonable Qualcomm/Android-style deployments these nodes are exposed to untrusted local apps for DSP offload, so a basic unprivileged local user is sufficient.\nUI:N - Once the attacker has local code execution and device-node access, triggering the ioctl path requires no victim action. No user needs to open a file, mount anything, or interact with attacker-controlled content.\nS:U - The vulnerability corrupts kernel-owned memory from within a kernel driver and is scored as a standard local kernel compromise. It does not require crossing a separate security authority such as guest-to-host or IOMMU isolation.\nC:H - The bug leaves a freed fastrpc_buf pointer reachable and later dereferenced/freed again, creating a kernel use-after-free/double-free condition. Per kernel scoring guidance, this kind of memory corruption is treated as capable of high-impact information disclosure.\nI:H - The stale pointer and double-free can corrupt kernel heap/DMA allocation state and may be shaped through heap reuse, making code execution or arbitrary kernel memory modification plausible. Per guidance, UAF/double-free memory corruption warrants high integrity impact.\nA:H - Even without full exploitation, the second dereference/free of an already freed kernel object can cause an oops, panic, or allocator corruption. This is a high availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:24:51.799Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4b8e527aca357a6488680713bd88007cf8f547fe"
        },
        {
          "url": "https://git.kernel.org/stable/c/0bdee4118340c5a756220c1b29a7dab86bb0aa65"
        },
        {
          "url": "https://git.kernel.org/stable/c/3a164f640953cc982804746e772d379171aff5c6"
        },
        {
          "url": "https://git.kernel.org/stable/c/f67d368d26764a357691b2b3a33d3cb55b435bfc"
        },
        {
          "url": "https://git.kernel.org/stable/c/ba2c83167b215da30fa2aae56b140198cf8d8408"
        }
      ],
      "title": "misc: fastrpc: possible double-free of cctx-\u003eremote_heap",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-31730",
    "datePublished": "2026-05-01T14:14:29.522Z",
    "dateReserved": "2026-03-09T15:48:24.135Z",
    "dateUpdated": "2026-08-05T12:24:51.799Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…