CVE-2026-31675
published 2026-04-25CVE-2026-31675: In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in packet corruption In netem_enqueue(), the…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_netem: fix out-of-bounds access in packet corruption
In netem_enqueue(), the packet corruption logic uses
get_random_u32_below(skb_headlen(skb)) to select an index for
modifying skb->data. When an AF_PACKET TX_RING sends fully non-linear
packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0.
Passing 0 to get_random_u32_below() takes the variable-ceil slow path
which returns an unconstrained 32-bit random integer. Using this
unconstrained value as an offset into skb->data results in an
out-of-bounds memory access.
Fix this by verifying skb_headlen(skb) is non-zero before attempting
to corrupt the linear data area. Fully non-linear packets will silently
bypass the corruption logic.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= c865e5d99e25a171e8262fc0f7ba608568633c64 < a14b56863348686dd0387eea8ce66b85cf455908 | a14b56863348686dd0387eea8ce66b85cf455908 |
| linux | linux | >= c865e5d99e25a171e8262fc0f7ba608568633c64 < 13a66ca1e235d4bcd53d12d4c68490cad7f8e46f | 13a66ca1e235d4bcd53d12d4c68490cad7f8e46f |
| linux | linux | >= c865e5d99e25a171e8262fc0f7ba608568633c64 < 3a2999704ac36cfb4041fed3652d26a3373e8d12 | 3a2999704ac36cfb4041fed3652d26a3373e8d12 |
| linux | linux | >= c865e5d99e25a171e8262fc0f7ba608568633c64 < 4fd258e281fa8bc15e9ce2c7691941537e9258ad | 4fd258e281fa8bc15e9ce2c7691941537e9258ad |
| linux | linux | >= c865e5d99e25a171e8262fc0f7ba608568633c64 < d64cb81dcbd54927515a7f65e5e24affdc73c14b | d64cb81dcbd54927515a7f65e5e24affdc73c14b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.16 < 6.6.134 | 6.6.134 |
| linux | linux_kernel | >= 6.13 < 6.18.22 | 6.18.22 |
| linux | linux_kernel | >= 6.19 < 6.19.12 | 6.19.12 |
| linux | linux_kernel | >= 6.7 < 6.12.81 | 6.12.81 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.6.133/6.12.80/6.18.21/6.19.11 netem_enqueue out-of-bounds (EUVD-2026-25642)
vuldb·2026-04-25
CVE-2026-31675 [LOW] Linux Kernel up to 6.6.133/6.12.80/6.18.21/6.19.11 netem_enqueue out-of-bounds (EUVD-2026-25642)
A vulnerability was found in Linux Kernel up to 6.6.133/6.12.80/6.18.21/6.19.11. It has been classified as critical. This affects the function netem_enqueue. This manipulation causes out-of-bounds read.
This vulnerability is handled as CVE-2026-31675. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-2gh3-wm75-4q8m: In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_netem: fix out-of-bounds access in packet corruption
In netem_enq
ghsa_unreviewed·2026-04-25
CVE-2026-31675 [HIGH] CWE-125 GHSA-2gh3-wm75-4q8m: In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_netem: fix out-of-bounds access in packet corruption
In netem_enq
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_netem: fix out-of-bounds access in packet corruption
In netem_enqueue(), the packet corruption logic uses
get_random_u32_below(skb_headlen(skb)) to select an index for
modifying skb->data. When an AF_PACKET TX_RING sends fully non-linear
packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0.
Passing 0 to get_random_u32_below() takes the variable-ceil slow path
which returns an unconstrained 32-bit random integer. Using this
unconstrained value as an offset into skb->data results in an
out-of-bounds memory access.
Fix this by verifying skb_headlen(skb) is non-zero before attempting
to corrupt the linear data area. Fully non-linear packets will silently
bypass the corruption logic.
Red Hat
kernel: net/sched: sch_netem: fix out-of-bounds access in packet corruption
vendor_redhat·2026-04-25·CVSS 7.0
CVE-2026-31675 [MEDIUM] CWE-1285 kernel: net/sched: sch_netem: fix out-of-bounds access in packet corruption
kernel: net/sched: sch_netem: fix out-of-bounds access in packet corruption
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_netem: fix out-of-bounds access in packet corruption
In netem_enqueue(), the packet corruption logic uses
get_random_u32_below(skb_headlen(skb)) to select an index for
modifying skb->data. When an AF_PACKET TX_RING sends fully non-linear
packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0.
Passing 0 to get_random_u32_below() takes the variable-ceil slow path
which returns an unconstrained 32-bit random integer. Using this
unconstrained value as an offset into skb->data results in an
out-of-bounds memory access.
Fix this by verifying skb_headlen(skb) is non-zero before attempting
to corrupt the linear data area. Fully non-li
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/13a66ca1e235d4bcd53d12d4c68490cad7f8e46fhttps://git.kernel.org/stable/c/3a2999704ac36cfb4041fed3652d26a3373e8d12https://git.kernel.org/stable/c/4fd258e281fa8bc15e9ce2c7691941537e9258adhttps://git.kernel.org/stable/c/a14b56863348686dd0387eea8ce66b85cf455908https://git.kernel.org/stable/c/d64cb81dcbd54927515a7f65e5e24affdc73c14b
2026-04-25
Published