CVE-2026-31395Patch(linux / linux_kernel)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-supplied 'type' field directly as an index into bp->bs_trace[] without bounds validation. The 'type' field is a 16-bit value extracted from DMA-mapped completion ring memory that the NIC writes directly to host RAM. A malicious or compromised NIC can supply any value from 0 to 65535, causing an out-of-bounds access into kernel heap memory. The bnxt_bs_trace_check_wrap() call then dereferences bs_trace->magic_byte and writes to bs_trace->last_offset and bs_trace->wrapped, leading to kernel memory corruption or a crash. Fix by adding a bounds check and defining BNXT_TRACE_MAX as DBG_LOG_BUFFER_FLUSH_REQ_TYPE_ERR_QPC_TRACE + 1 to cover all currently defined firmware trace types (0x0 through 0xc).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-03: 3Mentions · 2026-05-30: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-05-30: 1Technical Details · 2026-04-03: 1Technical Details · 2026-05-30: 104-0305-30
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-033
Disclosure1General1Patch1
2026-05-301
Patch1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-31395) https://vuldb.com/vuln/355166

    Post summary

    A new, critically-rated Linux kernel vulnerability (CVE-2026-31395) is reported, but the text provides no additional technical details, exploits, or mitigation guidance.

    01011114
    2.1K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity Linux kernel CVE-2026-31395 (CVSS 7.1) OOB access in bnxt_en driver allows malicious NIC to corrupt kernel memory via unbounded firmware trace type field. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/xRnrkIt01l

    Post summary

    The tweet announces a high‑severity Linux kernel vulnerability (CVE‑2026‑31395) that allows OOB access and kernel memory corruption, and urges an immediate patch.

    0000065
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-31395 In the Linux kernel, the following vulnerability has been resolve... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31395 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post merely acknowledges the existence of CVE-2026-31395 with a link to a vulnerability detail page, without providing technical specifics, exploit code, or remediation information.

    0000050
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31395 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DB… https://www.cve.org/CVERecord?id=CVE-2026-31395

    Post summary

    CVE‑2026‑31395 is a Linux kernel flaw involving an out‑of‑bounds access in the bnxt_en driver’s async event handler, which has now been resolved with a kernel patch.

    0000068
    56.9K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more