---
id: CVE-2026-31399
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvdimm/bus: Fix potential use after free in asynchronous initialization

  Dingisoul with KASAN reports a use after free if device_add() fails in
  nd_async_device_register…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvdimm/bus: Fix potential use after free in asynchronous initialization

  Dingisoul with KASAN reports a use after free if device_add() fails in
  nd_async_device_register…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.4.164, < 4.5'
  - 'linux_kernel >= 4.9.137, < 4.10'
  - 'linux_kernel >= 4.14.81, < 4.15'
  - 'linux_kernel >= 4.18.19, < 4.19'
  - 'linux_kernel >= 4.19.2, < 5.10.253'
  - 'linux_kernel >= 5.11, < 5.15.203'
  - 'linux_kernel >= 5.16, < 6.1.167'
  - 'linux_kernel >= 6.2, < 6.6.130'
  - 'linux_kernel >= 6.7, < 6.12.78'
  - 'linux_kernel >= 6.13, < 6.18.20'
  - 'linux_kernel >= 6.19, < 6.19.10'
  - linux_kernel = 7.0
patched:
  - linux_kernel 6.19.10
published: '2026-04-03'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31399'
references:
  - url: 'https://git.kernel.org/stable/c/2c638259ad750833fd46a0cf57672a618542d84c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6fc36c2a925ceaba203eb13d75a8f0879a2c121b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/84af19855d1abdee3c9d57c0684e2868e391793c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9a0fb16ba5b372465a3a1ecd761c6fa911a4ab4d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a226e5b49e5fe8c98b14f8507de670189d191348'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a36cf138500e56f50db9f9a33222df6969b38326'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a8aec14230322ed8f1e8042b6d656c1631d41163'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e48bf8f1d2b12c1c5ba1f609edbd4cde5dadc20e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00119
epssPercentile: 0.02042
ingestedAt: '2026-07-25T22:05:04.210Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

nvdimm/bus: Fix potential use after free in asynchronous initialization

Dingisoul with KASAN reports a use after free if device_add() fails in
nd_async_device_register().

Commit b6eae0f61db2 ("libnvdimm: Hold reference on parent while
scheduling async init") correctly added a reference on the parent device
to be held until asynchronous initialization was complete.  However, if
device_add() results in an allocation failure the ref count of the
device drops to 0 prior to the parent pointer being accessed.  Thus
resulting in use after free.

The bug bot AI correctly identified the fix.  Save a reference to the
parent pointer to be used to drop the parent reference regardless of the
outcome of device_add().

## Affected

- `linux_kernel >= 4.4.164, < 4.5`
- `linux_kernel >= 4.9.137, < 4.10`
- `linux_kernel >= 4.14.81, < 4.15`
- `linux_kernel >= 4.18.19, < 4.19`
- `linux_kernel >= 4.19.2, < 5.10.253`
- `linux_kernel >= 5.11, < 5.15.203`
- `linux_kernel >= 5.16, < 6.1.167`
- `linux_kernel >= 6.2, < 6.6.130`
- `linux_kernel >= 6.7, < 6.12.78`
- `linux_kernel >= 6.13, < 6.18.20`
- `linux_kernel >= 6.19, < 6.19.10`
- `linux_kernel = 7.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.10`
