{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-31501",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-03-09T15:48:24.104Z",
        "datePublished": "2026-04-22T13:54:21.749Z",
        "dateUpdated": "2026-08-05T12:23:04.740Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:23:04.740Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path\n\ncppi5_hdesc_get_psdata() returns a pointer into the CPPI descriptor.\nIn both emac_rx_packet() and emac_rx_packet_zc(), the descriptor is\nfreed via k3_cppi_desc_pool_free() before the psdata pointer is used\nby emac_rx_timestamp(), which dereferences psdata[0] and psdata[1].\nThis constitutes a use-after-free on every received packet that goes\nthrough the timestamp path.\n\nDefer the descriptor free until after all accesses through the psdata\npointer are complete. For emac_rx_packet(), move the free into the\nrequeue label so both early-exit and success paths free the descriptor\nafter all accesses are done. For emac_rx_packet_zc(), move the free to\nthe end of the loop body after emac_dispatch_skb_zc() (which calls\nemac_rx_timestamp()) has returned."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - The vulnerable code is in the Ethernet RX path and is reached by received network packets once RX hardware timestamping is enabled. In a reasonable PTP/industrial deployment, a remote network sender can trigger the timestamp path without local access.\nAC:L - The bug is not a race; the descriptor is freed before `psdata` is dereferenced on each timestamped RX packet. An attacker can reliably send packets to exercise the path.\nPR:N - The packet sender needs no privileges or authentication to reach the RX processing path. Enabling hardware timestamping requires CAP_NET_ADMIN, but that is a normal target configuration precondition rather than a privilege needed by the remote attacker.\nUI:N - No victim user action is required after the interface is running with RX timestamping enabled. Packet reception alone drives IRQ/NAPI processing into the vulnerable function.\nS:U - The impact remains within the same kernel/host security authority. This is not a VM escape, IOMMU bypass, or cross-scope boundary violation.\nC:H - This is a kernel use-after-free of a CPPI descriptor pointer used for RX metadata. Under the kernel scoring guidance, UAF of descriptor memory is treated as capable of exposing kernel or DMA-controlled memory state.\nI:H - Use-after-free in kernel RX descriptor lifetime is a memory-corruption class issue. Descriptor reuse and DMA interaction make high-integrity impact defensible under the required higher-severity scoring rule.\nA:H - Repeated network packets can repeatedly hit the freed-descriptor dereference in softirq/NAPI context. A kernel crash, RX path corruption, or device/network outage is a high availability impact."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/ti/icssg/icssg_common.c"
                    ],
                    "versions": [
                        {
                            "version": "46eeb90f03e03d5e8f7f9f1f0eb0792104fc5f86",
                            "lessThan": "d5827316debcb677679bb014885d7be92c410e11",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "46eeb90f03e03d5e8f7f9f1f0eb0792104fc5f86",
                            "lessThan": "eb8c426c9803beb171f89d15fea17505eb517714",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/ti/icssg/icssg_common.c"
                    ],
                    "versions": [
                        {
                            "version": "6.15",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.15",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.19.11",
                            "lessThanOrEqual": "6.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.15",
                                    "versionEndExcluding": "6.19.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.15",
                                    "versionEndExcluding": "7.0"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/d5827316debcb677679bb014885d7be92c410e11"
                },
                {
                    "url": "https://git.kernel.org/stable/c/eb8c426c9803beb171f89d15fea17505eb517714"
                }
            ],
            "title": "net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}