PT-2026-35020 · Linux+2 · Linux Kernel+2

CVE-2026-31668

·

Published

2026-04-04

·

Updated

2026-09-02

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the seg6 lwtunnel, a single dst cache per encap route is shared between the seg6 input core() and seg6 output core() functions. Because these two paths can perform post-encap SID lookups in different routing contexts, such as VRF table separation or ip rules matching on the ingress interface, the path that executes first populates the cache. The subsequent path then reuses this cached data without performing its own lookup, effectively bypassing the intended routing context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-83813
BDU:2026-10732
CVE-2026-31668
ECHO-1266-1F5A-2356
OESA-2026-2492
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
SUSE-SU-2026:2450-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8493-1
USN-8493-2
USN-8497-1
USN-8498-1
USN-8499-1
USN-8508-1
USN-8527-1
USN-8528-1
USN-8545-1
USN-8546-1
USN-8547-1
USN-8547-2
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1
USN-8633-1
USN-8633-2
USN-8635-1
USN-8645-1
USN-8666-1
USN-8666-2
USN-8666-3
USN-8667-1
USN-8715-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu