What is CVE-2026-31544?
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix NULL dereference on notify error path Since commit b5daf93b809d1 ("firmware: arm_scmi: Avoid notifier registration for unsupported events") the call chains leading to the helper __scmi_event_handler_get_ops expect an ERR_PTR to be returned on failure to get an handler for the requested event key, while the current helper can still return a NULL when no handler could be found or created. Fix by forcing an ERR_PTR return value when the handler reference is NULL.
Timeline
- 2026-04-24Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Linux Kernel
Remediation Steps
- Update SimpleHelp to latest stable version from vendor portal
- Review active remote support sessions for suspicious activity
- Audit user access logs for unauthorized administrative actions
- Implement IP whitelisting for SimpleHelp service access
- Deploy additional monitoring for remote session data exfiltration attempts
References
- https://git.kernel.org/stable/c/555317d6100164748f7d09f80142739bd29f0cda
- https://git.kernel.org/stable/c/70d9bd9a2e683afe6200b0c20af22f06f1a199a4
- https://git.kernel.org/stable/c/8414d2800c34528467df23ce6192c254a73e4459
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.simplehelp.net/support
- https://nvd.nist.gov/vuln/detail/CVE-2026-31544
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of April 2026 (April 27 – May 3)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.