PT-2026-34377 · Linux · Linux Kernel

CVE-2026-31472

·

Published

2026-03-02

·

Updated

2026-04-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the xfrm IPTFS component where the inner IPv4 header length in IPTFS payloads is not properly validated within the input process payload() function. A specially crafted ESP packet containing an inner IPv4 header with a tot len of 0 can trigger an infinite loop. This occurs because the data offset fails to advance, causing the system to spin indefinitely in the softirq context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12525
CVE-2026-31472

Affected Products

Linux Kernel