CVE-2026-31787, also tracked as XSA-487, is a double-free vulnerability in the Linux kernel Xen privcmd implementation. The vulnerable privcmd_vm_ops defines privcmd_close() as its .close callback but lacks both .may_split and .open callbacks. A userspace partial munmap() of a privcmd mapping therefore permits __split_vma() to split the virtual memory area. During splitting, vm_area_dup() duplicates vm_private_data without adjusting ownership of the pages array allocated by alloc_empty_pages(), leaving both VMAs referencing the same allocation. Closing the unmapped portion frees the array through privcmd_close(); subsequently destroying the surviving VMA repeats the cleanup using a dangling pointer and causes a double free.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A double-free vulnerability in the Linux kernel's Xen privcmd driver. A partial munmap() splits a virtual memory area (VMA), leaving both VMAs sharing the same pages-array pointer. Closing one frees the array; destroying the surviving VMA frees it again. The CVSS v3 score is 7.8, indicating local exploitation requiring low privileges, with high confidentiality, integrity, and availability impacts. The fix prevents VMA splitting through a .may_split callback.
A double-free vulnerability in the Linux kernel's Xen privcmd driver. A partial munmap() can split a virtual memory area, leaving both resulting mappings referencing the same allocated pages array. Closing one mapping frees the array; destroying the remaining mapping frees it again. The content assigns a CVSS v3 score of 7.8, with local access and low privileges required and potentially high confidentiality, integrity, and availability impact. The fix prevents VMA splitting through a .may_split callback.
A vulnerability addressed by the referenced CentOS 7/TuxCare advisory; no technical flaw details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.