CVE-2026-31413Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR maybe_fork_scalars() is called for both BPF_AND and BPF_OR when the source operand is a constant. When dst has signed range [-1, 0], it forks the verifier state: the pushed path gets dst = 0, the current path gets dst = -1. For BPF_AND this is correct: 0 & K == 0. For BPF_OR this is wrong: 0 | K == K, not 0. The pushed path therefore tracks dst as 0 when the runtime value is K, producing an exploitable verifier/runtime divergence that allows out-of-bounds map access. Fix this by passing env->insn_idx (instead of env->insn_idx + 1) to push_stack(), so the pushed path re-executes the ALU instruction with dst = 0 and naturally computes the correct result for any opcode.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Patch: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-12: 4Technical Details · 2026-04-12: 304-12
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Patch

    CVE-2026-31413 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR maybe_fork_scalars() is calle… https://www.cve.org/CVERecord?id=CVE-2026-31413

    Post summary

    CVE‑2026‑31413 was fixed in the Linux kernel addressing an unsound scalar forking issue in the BPF_OR function.

    00010360
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31413 Unsound Scalar Forking in Linux Kernel BPF Verifier for BPF_OR Operations https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31413

    Post summary

    A new CVE, 2026-31413, is disclosed that highlights an unsound scalar forking flaw in the Linux kernel BPF verifier affecting BPF_OR operations; no PoC, exploit, or patch information is mentioned.

    0001071
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-31413 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31413 #CVE-2026-31413 #CVE #CyberSecurity #InfoSec https://t.co/O8faqoii3w

    Post summary

    The post announces the existence of CVE-2026-31413, noting an unknown risk level and that it affects multiple unspecified products, and it directs readers to the NVD reference for details.

    0000028
    125 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31413 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR maybe_fork_scalars() is calle… https://www.cve.org/CVERecord?id=CVE-2026-31413 ----- Traducción: CVE-2026-31413 En … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-31413 as a resolved issue in the Linux kernel, describing the technical fix for unsound scalar forking in BPF_OR, but does not provide any PoC, exploit code, or patch details.

    0000045
    71 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more