PT-2026-35021 · Linux+3 · Linux Kernel+3

CVE-2026-31669

·

Publicado

2026-04-06

·

Atualizado

2026-08-30

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (versões afetadas não especificadas)
Description Um problema de slab-use-after-free existe na função inet lookup established(). O problema ocorre porque os sockets filhos de subfluxo MPTCP v6 são alocados via kmalloc em vez do cache slab TCPv6 devido a um erro na ordem de inicialização onde tcpv6 prot override.slab permanece NULL. Como o cache kmalloc-4k não possui a flag SLAB TYPESAFE BY RCU, a memória pode ser reutilizada imediatamente após ser liberada. Consequentemente, buscas ehash simultâneas sob rcu read lock podem acessar a memória liberada.
Recommendations No momento, não há informações sobre uma versão mais recente que contenha a correção para esta vulnerabilidade.

Exploit

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:26427
ALSA-2026:26428
ALSA-2026:27288
ALSA-2026:27789
AZL-83837
BDU:2026-10731
CVE-2026-31669
ECHO-E6A5-F9D1-FE42
OPENSUSE-SU-2026:20826-1
RHSA-2026:26427
RHSA-2026:26428
RHSA-2026:27288
RHSA-2026:27713
RHSA-2026:27789
RHSA-2026:33215
RHSA-2026:33900
RHSA-2026:34094
RHSA-2026:34095
RHSA-2026:35863
RHSA-2026:35894
RHSA-2026:35896
SUSE-SU-2026:2111-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2195-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8493-1
USN-8493-2
USN-8497-1
USN-8498-1
USN-8499-1
USN-8508-1
USN-8527-1
USN-8528-1
USN-8545-1
USN-8546-1
USN-8547-1
USN-8547-2
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1

Produtos afetados

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu