CVE-2026-31735: In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a
infovulnerability
security
Summary
A vulnerability exists in the Linux kernel's iommupt (IOMMU page table) code where the unmap operation can unmap more memory than requested, but the cache invalidation (gather) only clears the originally requested range instead of the entire unmapped area. This mismatch could leave stale memory translations cached, potentially causing security or stability issues, though the developers believe it may not be triggerable in practice.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
May 1, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-31735
First tracked: May 1, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 95%