CVE-2026-31402General(linux / linux_kernel)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operation responses. This size was calculated based on OPEN responses and does not account for LOCK denied responses, which include the conflicting lock owner as a variable-length field up to 1024 bytes (NFS4_OPAQUE_LIMIT). When a LOCK operation is denied due to a conflict with an existing lock that has a large owner, nfsd4_encode_operation() copies the full encoded response into the undersized replay buffer via read_bytes_from_xdr_buf() with no bounds check. This results in a slab-out-of-bounds write of up to 944 bytes past the end of the buffer, corrupting adjacent heap memory. This can be triggered remotely by an unauthenticated attacker with two cooperating NFSv4.0 clients: one sets a lock with a large owner string, then the other requests a conflicting lock to provoke the denial. We could fix this by increasing NFSD4_REPLAY_ISIZE to allow for a full opaque, but that would increase the size of every stateowner, when most lockowners are not that large. Instead, fix this by checking the encoded response length against NFSD4_REPLAY_ISIZE before copying into the replay buffer. If the response is too large, set rp_buflen to 0 to skip caching the replay payload. The status is still cached, and the client already received the correct response on the original request.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-03); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-03: 2Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-15: 1Mentions · 2026-05-26: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-26: 104-0304-0904-1004-1505-26
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-032
General1Patch1
2026-04-091
Disclosure1
2026-04-101
General1
2026-04-151
Disclosure1
2026-05-261
General1
Full discourse6 posts
  • Jeremy Shepherd 🔻🇵🇸@jeremy_wokka
    General

    @elhackernet La proxima vez que "escribes" un artículo sobre un bug en el kernel deberías incluir el CVE (en este caso, CVE-2026-31402) y tambien un vinculo a la pagina relevante en kernel punto org (https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit?id=5133b61aaf437e5f25b1b396b14242a6bb0508e2) O al menos que le digas al LLM que copias y pegas que lo incluya

    Post summary

    The user highlights that an article should reference CVE-2026-31402 and its commit page but provides no vulnerability details or exploitation information.

    1302711.0K
    43.7K followersView on X
  • Alex Matrosov@matrosov
    General

    Plenty. A few Linux-kernel examples: CVE-2024-53141 - netfilter ipset one-bit OOB write that Mythos programmed into a PTE flipper CVE-2026-31402 - 23-year-old remote heap overflow in NFSv4 LOCK CVE-2025-37899 - ksmbd concurrent-thread UAF, found by @seanhn The Mythos red-team blog has a bunch more (FreeBSD NFS RPCSEC_GSS, AF_UNIX MSG_OOB cross-cache, Firefox JIT spray) if you want to go deeper.

    Post summary

    The post lists several Linux kernel CVEs with concise technical descriptions, referencing additional information on a Mythos red‑team blog, but does not provide PoC, exploit code, active exploitation reports, or patch details.

    110101536
    20.1K followersView on X
  • Claude Code Lab 🔬@cc_lab_jp
    Disclosure

    【発見】AIが約23年間Linuxカーネルに潜んでた脆弱性を見つけたって…マジ?😱🔥 Anthropic研究者がClaude Codeでカーネルソースを分析した結果👇 ✅ NFSv4のヒープバッファオーバーフロー発見(CVE-2026-31402) ✅ 2003年から約23年間、人間レビューもすり抜けてた ✅ 複数のOSSプロジェクトから合計500超の高深刻度脆弱性をAIが検出 「こういう脆弱性、自分の人生で一度も見つけたことなかった」— Carlini氏 古いCコードベース持ってる人、AIでセキュリティ分析してみたくない…?🔥 https://red.anthropic.com/2026/zero-days/

    Post summary

    The post discloses a newly discovered NFSv4 heap buffer overflow (CVE‑2026‑31402) identified by an AI, providing basic technical details but no PoC, exploit, or patch information.

    0002080
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-31402 In the Linux kernel, the following vulnerability has been resolved: nfs... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31402 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post notes that CVE‑2026‑31402, a Linux kernel NFS issue, has been resolved, provides link references to Vulmon pages, but offers no technical details, PoC, or evidence of exploitation.

    0000153
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31402 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-b… https://www.cve.org/CVERecord?id=CVE-2026-31402

    Post summary

    The message announces that CVE-2026-31402, a heap overflow in the NFSv4.0 replay cache of the Linux kernel, has been fixed.

    0100091
    56.9K followersView on X
  • The Agent Times@TheAgentTimes
    Disclosure

    Anthropic's Claude Code discovered CVE-2026-31402, a remotely exploitable heap buffer overflow hidden in the Linux kernel's NFS implementation for 23 years, demonstrating that AI agents can perform deep cross-component security research tha... https://theagenttimes.com/articles/claude-code-uncovers-23-year-old-linux-kernel-flaw-signaling-00134994 #AIResearch https://t.co/TZ4B8bDYfb

    Post summary

    Anthropic's Claude Code identified a 23‑year‑old remote heap buffer overflow in the Linux kernel’s NFS system, but no PoC, active exploitation, or patch information was shared.

    000001
    79 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more