CVE-2026-31533Patch(linux / linux_kernel)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto requests"), has a use-after-free due to double cleanup of encrypt_pending and the scatterlist entry. When crypto_aead_encrypt() returns -EBUSY, the request is enqueued to the cryptd backlog and the async callback tls_encrypt_done() will be invoked upon completion. That callback unconditionally restores the scatterlist entry (sge->offset, sge->length) and decrements ctx->encrypt_pending. However, if tls_encrypt_async_wait() returns an error, the synchronous error path in tls_do_encryption() performs the same cleanup again, double-decrementing encrypt_pending and double-restoring the scatterlist. The double-decrement corrupts the encrypt_pending sentinel (initialized to 1), making tls_encrypt_async_wait() permanently skip the wait for pending async callbacks. A subsequent sendmsg can then free the tls_rec via bpf_exec_tx_verdict() while a cryptd callback is still pending, resulting in a use-after-free when the callback fires on the freed record. Fix this by skipping the synchronous cleanup when the -EBUSY async wait returns an error, since the callback has already handled encrypt_pending and sge restoration.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-23); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-05-01: 1Mentions · 2026-06-19: 1Active Exploitation · 2026-04-24: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-06-19: 1Technical Details · 2026-05-01: 104-2304-2405-0106-19
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-04-241
Active Exploitation1
2026-05-011
Patch1
2026-06-191
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Não pode reiniciar seu Oracle Linux 9 agora? Aprenda a mitigar CVE-2026-31504, CVE-2026-31533 e outras com iptables e ajustes de sysctl. Script incluso. Saiba mais: -> http://tinyurl.com/4zhwpk5s https://t.co/pAPFFk5LCH

    Post summary

    The tweet offers a mitigation script and guidance to patch Oracle Linux 9 for CVE-2026-31504 and CVE-2026-31533 using iptables and sysctl tweaks.

    1000060
    1.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Linux Kernel (CVE-2026-31533) https://vuldb.com/vuln/359162

    Post summary

    The text announces a newly disclosed Linux Kernel vulnerability (CVE-2026-31533) with higher severity and links to a database entry.

    0000177
    2.1K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔥 CVE-2026-31533: a Linux kTLS use-after-free… and now Microsoft’s “security update guide” is babysitting the kernel too. Translation: your cloud isn’t safer, it’s just logged. https://windowsforum.com/threads/cve-2026-31533-linux-ktls-use-after-free-now-hits-microsoft-centric-patch-plans.416160/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MsrcAdvisory #LinuxKernelSecurity #KtlsUseAfterFree #CryptoBacklog https://t.co/pxHYxVLRJK

    Post summary

    The tweet announces that Microsoft’s security update guide addresses the Linux kTLS use‑after‑free vulnerability (CVE‑2026‑31533), highlighting that the issue has been patched but remains a concern for cloud environments until applied.

    0000023
    1.1K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting Linux Kernel (CVE-2026-31533) https://vuldb.com/vuln/359162/cti

    Post summary

    The post reports elevated, real‑world activity targeting Linux Kernel via CVE‑2026‑31533.

    0000069
    2.1K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more