{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31730", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.135Z", "datePublished": "2026-05-01T14:14:29.522Z", "dateUpdated": "2026-08-05T12:24:51.799Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:24:51.799Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: possible double-free of cctx->remote_heap\n\nfastrpc_init_create_static_process() may free cctx->remote_heap on the\nerr_map path but does not clear the pointer. Later, fastrpc_rpmsg_remove()\nfrees cctx->remote_heap again if it is non-NULL, which can lead to a\ndouble-free if the INIT_CREATE_STATIC ioctl hits the error path and the rpmsg\ndevice is subsequently removed/unbound.\nClear cctx->remote_heap after freeing it in the error path to prevent the\nlater cleanup from freeing it again.\n\nThis issue was found by an in-house analysis workflow that extracts AST-based\ninformation and runs static checks, with LLM assistance for triage, and was\nconfirmed by manual code review.\nNo hardware testing was performed." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - FastRPC is reached by a local process opening the fastrpc misc device and issuing FASTRPC_IOCTL_INIT_CREATE_STATIC through the ioctl path. There is no network, adjacent, or physical packet path to this driver entry point.\nAC:L - No race is required; the attacker controls the ioctl arguments and can drive the error path that frees cctx->remote_heap while leaving the stale pointer in the vulnerable code. The stale pointer can then be reached again by retrying the ioctl or during rpmsg teardown, so exploitation does not depend on conditions outside the attacker's practical control.\nPR:L - The driver path has no capable() or namespace privilege check; access is gated only by the fastrpc device node. In reasonable Qualcomm/Android-style deployments these nodes are exposed to untrusted local apps for DSP offload, so a basic unprivileged local user is sufficient.\nUI:N - Once the attacker has local code execution and device-node access, triggering the ioctl path requires no victim action. No user needs to open a file, mount anything, or interact with attacker-controlled content.\nS:U - The vulnerability corrupts kernel-owned memory from within a kernel driver and is scored as a standard local kernel compromise. It does not require crossing a separate security authority such as guest-to-host or IOMMU isolation.\nC:H - The bug leaves a freed fastrpc_buf pointer reachable and later dereferenced/freed again, creating a kernel use-after-free/double-free condition. Per kernel scoring guidance, this kind of memory corruption is treated as capable of high-impact information disclosure.\nI:H - The stale pointer and double-free can corrupt kernel heap/DMA allocation state and may be shaped through heap reuse, making code execution or arbitrary kernel memory modification plausible. Per guidance, UAF/double-free memory corruption warrants high integrity impact.\nA:H - Even without full exploitation, the second dereference/free of an already freed kernel object can cause an oops, panic, or allocator corruption. This is a high availability impact." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/misc/fastrpc.c" ], "versions": [ { "version": "0871561055e666da421d779397efcc1e5e964cab", "lessThan": "4b8e527aca357a6488680713bd88007cf8f547fe", "status": "affected", "versionType": "git" }, { "version": "0871561055e666da421d779397efcc1e5e964cab", "lessThan": "0bdee4118340c5a756220c1b29a7dab86bb0aa65", "status": "affected", "versionType": "git" }, { "version": "0871561055e666da421d779397efcc1e5e964cab", "lessThan": "3a164f640953cc982804746e772d379171aff5c6", "status": "affected", "versionType": "git" }, { "version": "0871561055e666da421d779397efcc1e5e964cab", "lessThan": "f67d368d26764a357691b2b3a33d3cb55b435bfc", "status": "affected", "versionType": "git" }, { "version": "0871561055e666da421d779397efcc1e5e964cab", "lessThan": "ba2c83167b215da30fa2aae56b140198cf8d8408", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/misc/fastrpc.c" ], "versions": [ { "version": "6.2", "status": "affected" }, { "version": "0", "lessThan": "6.2", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.134", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.81", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.22", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.19.12", "lessThanOrEqual": "6.19.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.2", "versionEndExcluding": "6.6.134" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.2", "versionEndExcluding": "6.12.81" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.2", "versionEndExcluding": "6.18.22" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.2", "versionEndExcluding": "6.19.12" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.2", "versionEndExcluding": "7.0" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/4b8e527aca357a6488680713bd88007cf8f547fe" }, { "url": "https://git.kernel.org/stable/c/0bdee4118340c5a756220c1b29a7dab86bb0aa65" }, { "url": "https://git.kernel.org/stable/c/3a164f640953cc982804746e772d379171aff5c6" }, { "url": "https://git.kernel.org/stable/c/f67d368d26764a357691b2b3a33d3cb55b435bfc" }, { "url": "https://git.kernel.org/stable/c/ba2c83167b215da30fa2aae56b140198cf8d8408" } ], "title": "misc: fastrpc: possible double-free of cctx->remote_heap", "x_generator": { "engine": "bippy-1.2.0" } } } }