Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-31562

5.5 · MEDIUM
Published Apr 24, 2026 linux CWE-476 EPSS 0.12% (2th pctl)

Overview

CVE-2026-31562 is a medium-severity vulnerability affecting linux linux_kernel. It was published on April 24, 2026 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register

The call to mipi_dsi_host_register triggers a callback to mtk_dsi_bind,

which uses dev_get_drvdata to retrieve the mtk_dsi struct, so this

structure needs to be stored inside the driver data before invoking it.

As drvdata is currently uninitialized it leads to a crash when

registering the DSI DRM encoder right after acquiring

the mode_config.idr_mutex, blocking all subsequent DRM operations.

Fixes the following crash during mediatek-drm probe (tested on Xiaomi

Smart Clock x04g):

Unable to handle kernel NULL pointer dereference at virtual address

0000000000000040

[...]

Modules linked in: mediatek_drm(+) drm_display_helper cec drm_client_lib

drm_dma_helper drm_kms_helper panel_simple

[...]

Call trace:

drm_mode_object_add+0x58/0x98 (P)

__drm_encoder_init+0x48/0x140

drm_encoder_init+0x6c/0xa0

drm_simple_encoder_init+0x20/0x34 [drm_kms_he

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 6.9.1, < 6.18.21 Affected

Frequently Asked Questions

What is CVE-2026-31562?

CVE-2026-31562 is a medium-severity vulnerability affecting linux linux_kernel. It was published on April 24, 2026 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2026-31562?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-31562?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-31562?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-31562 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.