CVE-2026-31730 Details
Description
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: possible double-free of cctx->remote_heap fastrpc_init_create_static_process() may free cctx->remote_heap on the err_map path but does not clear the pointer. Later, fastrpc_rpmsg_remove() frees cctx->remote_heap again if it is non-NULL, which can lead to a double-free if the INIT_CREATE_STATIC ioctl hits the error path and the rpmsg device is subsequently removed/unbound. Clear cctx->remote_heap after freeing it in the error path to prevent the later cleanup from freeing it again. This issue was found by an in-house analysis workflow that extracts AST-based information and runs static checks, with LLM assistance for triage, and was confirmed by manual code review. No hardware testing was performed.
A double-free vulnerability has been identified in the Linux kernel's fastrpc subsystem, specifically in versions 6.2 and later. The issue arises in the 'fastrpc_init_create_static_process' function, which can free the 'remote_heap' pointer without clearing it. If the 'INIT_CREATE_STATIC' ioctl encounters an error and the associated rpmsg device is removed, the 'remote_heap' can be freed again, leading to a double-free condition. This vulnerability was discovered through static analysis and manual code review.
Users can apply the available patch, which clears the 'remote_heap' pointer after freeing it in the error path, to prevent the double-free condition. The patched version can be obtained from the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0bdee4118340c5a756220c1b29a7dab86bb0aa65 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3a164f640953cc982804746e772d379171aff5c6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4b8e527aca357a6488680713bd88007cf8f547fe | kernel.org | Patch |
| https://git.kernel.org/stable/c/ba2c83167b215da30fa2aae56b140198cf8d8408 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f67d368d26764a357691b2b3a33d3cb55b435bfc | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-415 | Double Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.2, < 6.6.134 >= 6.7, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | CVE Modified | kernel.org |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | kernel.org |