PT-2026-35144 · Linux+3 · Linux Kernel+3

CVE-2026-31684

·

Published

2026-04-02

·

Updated

2026-08-25

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the tcf csum act() function where nested VLAN headers are processed directly from skb->data when a socket buffer still contains in-payload VLAN tags. The system reads vlan->h vlan encapsulated proto and pulls VLAN HLEN bytes without verifying that the complete VLAN header is present in the linear area. If only a portion of an inner VLAN header is linearized, accessing h vlan encapsulated proto reads beyond the linear area, and the subsequent skb pull(VLAN HLEN) operation may violate socket buffer invariants.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21556
ALSA-2026:21557
ALSA-2026:21706
ALSA-2026:21745
AZL-84222
BDU:2026-10723
CVE-2026-31684
ECHO-8125-2987-ADB4
OESA-2026-2581
OESA-2026-2582
OPENSUSE-SU-2026:20826-1
RHSA-2026:21556
RHSA-2026:21557
RHSA-2026:21706
RHSA-2026:21745
RHSA-2026:40068
RHSA-2026:41234
RHSA-2026:41235
RHSA-2026:43231
RHSA-2026:44694
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8665-1
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu