CVE-2026-31429Patch(linux / linux_kernel)

MEDIUMCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 value (e.g. 704 on x86_64) to avoid collisions with generic kmalloc bucket sizes. This ensures that skb_kfree_head() can reliably use skb_end_offset to distinguish skb heads allocated from skb_small_head_cache vs. generic kmalloc caches. However, when KFENCE is enabled, kfence_ksize() returns the exact requested allocation size instead of the slab bucket size. If a caller (e.g. bpf_test_init) allocates skb head data via kzalloc() and the requested size happens to equal SKB_SMALL_HEAD_CACHE_SIZE, then slab_build_skb() -> ksize() returns that exact value. After subtracting skb_shared_info overhead, skb_end_offset ends up matching SKB_SMALL_HEAD_HEADROOM, causing skb_kfree_head() to incorrectly free the object to skb_small_head_cache instead of back to the original kmalloc cache, resulting in a slab cross-cache free: kmem_cache_free(skbuff_small_head): Wrong slab cache. Expected skbuff_small_head but got kmalloc-1k Fix this by always calling kfree(head) in skb_kfree_head(). This keeps the free path generic and avoids allocator-specific misclassification for KFENCE objects.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-20); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-20: 2Mentions · 2026-04-22: 2Mentions · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-24: 1Exploit Tool / Code · 2026-04-24: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-22: 2Technical Details · 2026-04-24: 104-2004-2204-24
Signal classification4 categories
Patch
240.0%
Disclosure
120.0%
General
120.0%
PoC
120.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-202
Disclosure1Patch1
2026-04-222
General1Patch1
2026-04-241
PoC1
Full discourse5 posts
  • bluedragonsec@bluedragonsec
    PoC

    https://github.com/bluedragonsecurity/CVE-2026-31429-POC POC for CVE-2026-31429 (Linux Kernel >= 6.3 < 6.12.82 Slab Cross-Cache Confusion) - vulnerability discovered by Antonius - w1sdom - http://bluedragonsec.com

    Post summary

    A proof‑of‑concept demonstrating the Slab Cross‑Cache Confusion flaw in Linux kernels 6.3 through 6.12.82 is publicly available on GitHub.

    00020235
    64 followersView on X
  • WindowsForum@windowsforum
    Patch

    🐧 Kernel edge-case = where bugs breed. CVE-2026-31429 fixes a KFENCE slab mis-ID in skb_kfree_head: misclassify one pointer, and suddenly your networking’s “free” is on the wrong owner. https://windowsforum.com/threads/cve-2026-31429-fix-linux-skb-head-misclassified-with-kfence.414685/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernelSecurity #NetworkingSkb #Kfence #Cve202631429 https://t.co/oGPshfKYo9

    Post summary

    The tweet announces a fix for CVE-2026-31429, detailing a KFENCE slab misidentification in the Linux kernel’s networking stack, and links to a forum thread discussing the patch.

    0000044
    1.1K followersView on X
  • WindowsForum@windowsforum
    General

    🪟 CVE-2026-31429 is the classic “small networking bug, big security mess.” Linux tried to be clever about freeing skb memory—KFENCE proves ‘heuristics’ aren’t trust. kfree it. https://windowsforum.com/threads/cve-2026-31429-kernel-skb-head-kfence-wrong-cache-free-fix-uses-kfree.414684/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernelSecurity #Kfence #SkbMemoryManagement #Cve202631429 https://t.co/xLuUDvTmac

    Post summary

    The tweet discusses CVE‑2026‑31429 as a networking memory bug involving KFENCE, but provides no PoC, exploit, or patch details—all it offers is a commentary on the technical nature of the flaw.

    0000051
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31429 Linux Kernel SKB Head Cross-Cache Free Vulnerability with KFENCE https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31429 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-31429, a Linux kernel vulnerability labeled as a SKB head cross-cache free issue, and provides links to vulnerability details and notifications.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31429 In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intenti… https://www.cve.org/CVERecord?id=CVE-2026-31429

    Post summary

    The entry states that CVE-2026-31429 has been fixed in the Linux kernel with a patch addressing a cross‑cache free issue in skb.

    0000089
    57.2K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more