CVE-2026-31417
high
CVSS v3
7.5
CVSS v4 NEW
โ
VIR risk
7.5
Description
In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Add a check to ensure that `x25_sock.fraglen` does not overflow. The `fraglen` also needs to be resetted when purging `fragment_queue` in `x25_clear_queues()`.
Predictions
Exploit likelihood
83%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 6.1.170-1 |
| debian | forky | fixed | 6.19.12-1 |
| debian | sid | fixed | 6.19.12-1 |
| debian | trixie | fixed | 6.12.85-1 |
| debian | bullseye | fixed | 6.1.170-1~deb11u1 |
| linux-kernel | affected | 5.10.253 | |
| linux-kernel | 2.6.12 | affected | |
| linux-kernel | 7.0 | affected | |
References
- https://git.kernel.org/stable/c/1734bd85c5e0a7a801295b729efb56b009cb8fc3
- https://git.kernel.org/stable/c/4e2d1bcef78d21247fe8fef13bc7ed95885df2b5
- https://git.kernel.org/stable/c/6e568835ea54a3e1d08e310e34f95d434e739477
- https://git.kernel.org/stable/c/798d613afb64b01a203f448fb0f43c37c6afe79d
- https://git.kernel.org/stable/c/8c92969c197b91c134be27dc3afb64ab468853a9
- https://git.kernel.org/stable/c/96fc16370b0bceb289c7e0479bd0540b81e257aa
- https://git.kernel.org/stable/c/a1822cb524e89b4cd2cf0b82e484a2335496a6d9
- https://git.kernel.org/stable/c/f953f11ccf4afe6feb635c08145f4240d9a6b544
- https://www.suse.com/security/cve/CVE-2026-31417.html
- https://security-tracker.debian.org/tracker/CVE-2026-31417
CWEs
CWE-191
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.