PT-2026-35021 · Linux+3 · Linux Kernel+3

CVE-2026-31669

·

Published

2026-04-06

·

Updated

2026-08-30

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab-use-after-free issue exists in the inet lookup established() function. The problem occurs because MPTCP v6 subflow child sockets are allocated via kmalloc instead of the TCPv6 slab cache due to an initialization order error where tcpv6 prot override.slab remains NULL. Because the kmalloc-4k cache lacks the SLAB TYPESAFE BY RCU flag, memory can be reused immediately after being freed. Consequently, concurrent ehash lookups under rcu read lock may access freed memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:26427
ALSA-2026:26428
ALSA-2026:27288
ALSA-2026:27789
AZL-83837
BDU:2026-10731
CVE-2026-31669
ECHO-E6A5-F9D1-FE42
OPENSUSE-SU-2026:20826-1
RHSA-2026:26427
RHSA-2026:26428
RHSA-2026:27288
RHSA-2026:27713
RHSA-2026:27789
RHSA-2026:33215
RHSA-2026:33900
RHSA-2026:34094
RHSA-2026:34095
RHSA-2026:35863
RHSA-2026:35894
RHSA-2026:35896
SUSE-SU-2026:2111-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2195-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8493-1
USN-8493-2
USN-8497-1
USN-8498-1
USN-8499-1
USN-8508-1
USN-8527-1
USN-8528-1
USN-8545-1
USN-8546-1
USN-8547-1
USN-8547-2
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu