CVE-2026-31679General(linux / linux_kernel)

LOWCVSS 7.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: openvswitch: validate MPLS set/set_masked payload length validate_set() accepted OVS_KEY_ATTR_MPLS as variable-sized payload for SET/SET_MASKED actions. In action handling, OVS expects fixed-size MPLS key data (struct ovs_key_mpls). Use the already normalized key_len (masked case included) and reject non-matching MPLS action key sizes. Reject invalid MPLS action payload lengths early.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-25: 4Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-25: 204-25
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • VulDB 🛡@vuldb
    General

    Some increased actor activities are shown targeting Linux Kernel (CVE-2026-31679) https://vuldb.com/vuln/359584/cti

    Post summary

    The post notes increased actor interest in Linux Kernel CVE-2026-31679, linking to a vulnerability page but providing no exploitation, patch, or technical details.

    0100090
    2.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31679 In the Linux kernel, the following vulnerability has been resolved: openvswitch: validate MPLS set/set_masked payload length validate_set() accepted OVS_KEY_ATTR_MP… https://www.cve.org/CVERecord?id=CVE-2026-31679

    Post summary

    CVE-2026-31679, a vulnerability in openvswitch’s MPLS payload handling, has been resolved by the Linux kernel maintainers; no PoC, exploit, or active exploitation is reported.

    0000076
    57.2K followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Linux Kernel (CVE-2026-31679) https://vuldb.com/vuln/359584

    Post summary

    The text merely notes an increased severity for CVE-2026-31679 and provides a link, with no detailed or actionable information.

    0000086
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31679 MPLS Payload Length Validation Vulnerability in Linux Ker... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31679 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-31679, describing it as an MPLS Payload Length Validation Vulnerability in the Linux Kernel, and links to Vulmon for more information.

    0000043
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more