cbcvebase.
CVE-2026-31675
published 2026-04-25

CVE-2026-31675: In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in packet corruption In netem_enqueue(), the…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in packet corruption In netem_enqueue(), the packet corruption logic uses get_random_u32_below(skb_headlen(skb)) to select an index for modifying skb->data. When an AF_PACKET TX_RING sends fully non-linear packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0. Passing 0 to get_random_u32_below() takes the variable-ceil slow path which returns an unconstrained 32-bit random integer. Using this unconstrained value as an offset into skb->data results in an out-of-bounds memory access. Fix this by verifying skb_headlen(skb) is non-zero before attempting to corrupt the linear data area. Fully non-linear packets will silently bypass the corruption logic.

Affected

12 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= c865e5d99e25a171e8262fc0f7ba608568633c64 < a14b56863348686dd0387eea8ce66b85cf455908a14b56863348686dd0387eea8ce66b85cf455908
linuxlinux>= c865e5d99e25a171e8262fc0f7ba608568633c64 < 13a66ca1e235d4bcd53d12d4c68490cad7f8e46f13a66ca1e235d4bcd53d12d4c68490cad7f8e46f
linuxlinux>= c865e5d99e25a171e8262fc0f7ba608568633c64 < 3a2999704ac36cfb4041fed3652d26a3373e8d123a2999704ac36cfb4041fed3652d26a3373e8d12
linuxlinux>= c865e5d99e25a171e8262fc0f7ba608568633c64 < 4fd258e281fa8bc15e9ce2c7691941537e9258ad4fd258e281fa8bc15e9ce2c7691941537e9258ad
linuxlinux>= c865e5d99e25a171e8262fc0f7ba608568633c64 < d64cb81dcbd54927515a7f65e5e24affdc73c14bd64cb81dcbd54927515a7f65e5e24affdc73c14b
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.16 < 6.6.1346.6.134
linuxlinux_kernel>= 6.13 < 6.18.226.18.22
linuxlinux_kernel>= 6.19 < 6.19.126.19.12
linuxlinux_kernel>= 6.7 < 6.12.816.12.81

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.