CVE-2026-31503Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: udp: Fix wildcard bind conflict check when using hash2 When binding a udp_sock to a local address and port, UDP uses two hashes (udptable->hash and udptable->hash2) for collision detection. The current code switches to "hash2" when hslot->count > 10. "hash2" is keyed by local address and local port. "hash" is keyed by local port only. The issue can be shown in the following bind sequence (pseudo code): bind(fd1, "[fd00::1]:8888") bind(fd2, "[fd00::2]:8888") bind(fd3, "[fd00::3]:8888") bind(fd4, "[fd00::4]:8888") bind(fd5, "[fd00::5]:8888") bind(fd6, "[fd00::6]:8888") bind(fd7, "[fd00::7]:8888") bind(fd8, "[fd00::8]:8888") bind(fd9, "[fd00::9]:8888") bind(fd10, "[fd00::10]:8888") /* Correctly return -EADDRINUSE because "hash" is used * instead of "hash2". udp_lib_lport_inuse() detects the * conflict. */ bind(fail_fd, "[::]:8888") /* After one more socket is bound to "[fd00::11]:8888", * hslot->count exceeds 10 and "hash2" is used instead. */ bind(fd11, "[fd00::11]:8888") bind(fail_fd, "[::]:8888") /* succeeds unexpectedly */ The same issue applies to the IPv4 wildcard address "0.0.0.0" and the IPv4-mapped wildcard address "::ffff:0.0.0.0". For example, if there are existing sockets bound to "192.168.1.[1-11]:8888", then binding "0.0.0.0:8888" or "[::ffff:0.0.0.0]:8888" can also miss the conflict when hslot->count > 10. TCP inet_csk_get_port() already has the correct check in inet_use_bhash2_on_bind(). Rename it to inet_use_hash2_on_bind() and move it to inet_hashtables.h so udp.c can reuse it in this fix.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-23)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 1Mentions · 2026-04-23: 2Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2204-23
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-232
Disclosure1General1
Full discourse3 posts
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-31503 is the kind of “minor” Linux networking bug that turns into a full-blown ops headache: hash2 makes UDP port collision detection blink. Wildcard binds slipping past “already in use” is chaos. https://windowsforum.com/threads/cve-2026-31503-udp-wildcard-bind-conflict-bypass-when-hash2-activates.414825/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #WildcardBind #UdpNetworking https://t.co/Wubby1OP5P

    Post summary

    CVE-2026‑31503 is a Linux kernel networking bug that disrupts UDP port collision detection via hash2, enabling wildcard bind conflicts, and this thread highlights the technical aspects of the issue.

    0000044
    1.1K followersView on X
  • WindowsForum@windowsforum
    General

    🪟 Another Linux CVE? Yep—because nothing screams “security” like the kernel doing math with thresholds and forgetting wildcard conflicts. Logic bugs = stealthy downtime for anyone with UDP apps. https://windowsforum.com/threads/cve-2026-31503-linux-udp-wildcard-bind-conflicts-missed-on-hash2-threshold.414823/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #KernelSecurity #LinuxNetworking #UdpBind #WildcardBind https://t.co/S1g0luLzXs

    Post summary

    A brief mention of a Linux socket bug in a tweet with no supporting technical details or evidence of exploitation, making it a general note rather than specific actionable intelligence.

    0000041
    1.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31503 In the Linux kernel, the following vulnerability has been resolved: udp: Fix wildcard bind conflict check when using hash2 When binding a udp_sock to a local addres… https://www.cve.org/CVERecord?id=CVE-2026-31503

    Post summary

    CVE‑2026‑31503 in the Linux kernel has been fixed; no evidence of PoC, exploit code, or active exploitation, but a patch is confirmed.

    00000107
    57.2K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.33--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more