【活用ガイド】

JVNDB-2026-013295

LinuxのLinux Kernelにおける無限ループに関する脆弱性

概要

Linuxカーネルにおいて、以下の脆弱性が修正されました。wifi: wlcoreにおいて、十分なヘッドルームがない場合に-EAGAINではなく-ENOMEMを返すように変更されました。アップストリームのコミットe75665dd0968("wifi: wlcore: ensure skb headroom before skb_push")以来、wl1271_tx_allocate()およびそれに伴うwl1271_prepare_tx_frame()は、pskb_expand_head()が失敗した場合に-EAGAINを返します。しかし、wlcore_tx_work_locked()では、wl1271_prepare_tx_frame()からの-EAGAINの戻り値を集約バッファがいっぱいであると解釈しています。これによりコードはバッファをフラッシュし、skbをキューの先頭に戻し、同じskbをタイトなwhileループ内で即座に再試行します。wlcore_tx_work_locked()はwl-mutexを保持しており、再試行はGFP_ATOMICで即座に行われるため、無限ループによるCPUのソフトロックアップが発生します。パケットを破棄してループを終了させるため、代わりに-ENOMEMを返します。この問題はv6.18.yへのバックポートをレビュー中に、gemini-3.1-proに基づく実験的コードレビューエージェントによって発見されました。
CVSS による深刻度 (CVSS とは?)

CVSS v3 による深刻度
基本値: 7.5 (重要) [その他]
  • 攻撃元区分: ネットワーク
  • 攻撃条件の複雑さ: 低
  • 攻撃に必要な特権レベル: 不要
  • 利用者の関与: 不要
  • 影響の想定範囲: 変更なし
  • 機密性への影響(C): なし
  • 完全性への影響(I): なし
  • 可用性への影響(A): 高
影響を受けるシステム


Linux
  • Linux Kernel 5.10.250 以上 5.10.253 未満
  • Linux Kernel 5.15.200 以上 5.15.203 未満
  • Linux Kernel 6.1.163 以上 6.1.167 未満
  • Linux Kernel 6.12.70 以上 6.12.78 未満
  • Linux Kernel 6.18.10 以上 6.18.20 未満
  • Linux Kernel 6.19.1 以上 6.19.10 未満
  • Linux Kernel 6.6.124 以上 6.6.130 未満
  • Linux Kernel 6.19
  • Linux Kernel 7.0

想定される影響

当該ソフトウェアが扱う情報について、外部への漏えいは発生しません。
また、当該ソフトウェアが扱う情報について、書き換えは発生しません。
さらに、当該ソフトウェアが完全に停止する可能性があります。
そして、この脆弱性を悪用した攻撃の影響は、他のソフトウェアには及びません。
対策

リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
ベンダ情報

CWEによる脆弱性タイプ一覧  CWEとは?

  1. 無限ループ(CWE-835) [NVD評価]
共通脆弱性識別子(CVE)  CVEとは?

  1. CVE-2026-31552
参考情報

  1. National Vulnerability Database (NVD) : CVE-2026-31552
  2. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/f2c06d718a7b85cbc59ceaa2ff3f46b178ac709c)
  3. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/46c670ff1ff466e5eccb3940f726586473dc053c)
  4. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/ceb46b40b021d21911ff8608ce4ed33c1264ad2f)
  5. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/980f793645540ca7a6318165cc12f49d5febeb99)
  6. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/a6dc74209462c4fe5a88718d2f3a5286886081c8)
  7. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/12f9eef39e49716c763714bfda835a733d5f6dea)
  8. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/cfa64e2b3717be1da7c4c1aff7268a009e8c1610)
  9. 関連文書 : wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/deb353d9bb009638b7762cae2d0b6e8fdbb41a69)
更新履歴

  • [2026年04月30日]
      掲載