What is CVE-2026-31545?
In the Linux kernel, the following vulnerability has been resolved: NFC: nxp-nci: allow GPIOs to sleep Allow the firmware and enable GPIOs to sleep. This fixes a `WARN_ON' and allows the driver to operate GPIOs which are connected to I2C GPIO expanders. -- >8 -- kernel: WARNING: CPU: 3 PID: 2636 at drivers/gpio/gpiolib.c:3880 gpiod_set_value+0x88/0x98 -- >8 --
Timeline
- 2026-04-24Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Linux Kernel
Remediation Steps
- Contact Carlson Software for VASCO-B firmware updates addressing critical functions
- Validate GNSS signal integrity and receiver authentication mechanisms
- Implement network-level monitoring of GNSS receiver communications
- Restrict device to trusted control networks with strict firewall policies
- Document baseline device behavior for anomaly detection
References
- https://git.kernel.org/stable/c/0c2320c3c860d281cbc2f49fc574c1947a6b9e2a
- https://git.kernel.org/stable/c/2a175bc3c338c6b2bc55004e93dd35a2467bdca2
- https://git.kernel.org/stable/c/4de9ed2ea22d611b4149969266b45a86ea8daf35
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-02.json
- https://www.carlsonsw.com/support
- https://nvd.nist.gov/vuln/detail/CVE-2026-31545
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of April 2026 (April 27 – May 3)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.