CVE-2026-31680Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and prints `fl->opt->opt_nflen` when an option block is present. Exclusive flowlabels currently free `fl->opt` as soon as `fl->users` drops to zero in `fl_release()`. However, the surrounding `struct ip6_flowlabel` remains visible in the global hash table until later garbage collection removes it and `fl_free_rcu()` finally tears it down. A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that early `kfree()` and dereference freed option state, triggering a crash in `ip6fl_seq_show()`. Fix this by keeping `fl->opt` alive until `fl_free_rcu()`. That matches the lifetime already required for the enclosing flowlabel while readers can still reach it under RCU.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-25: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-25: 2Technical Details · 2026-04-28: 104-2504-28
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-252
Disclosure1Patch1
2026-04-281
Disclosure1
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🟠 الثغرة الرابعة: (CVE-2026-31680) | التقييم: 7.8 (عالية الخطورة) 💻 نوع الهجوم: هجوم محلي (Local Attack). ⚙️ وصف الثغرة: تحدث بسبب خطأ في "التوقيت"، حيث يحاول النظام قراءة معلومات كان من المفترض أن تُحذف، مما يؤدي إلى تداخل في الذاكرة. 🎯 النتيجة: تسبب انهيار النظام (Crash) أو تمكين المستخدم العادي من الوصول لبيانات حساسة لا تخصه.

    Post summary

    The post announces CVE-2026-31680, a severe (7.8/10) local memory corruption flaw caused by a timing error, leading to crashes or unauthorized data access.

    100401.5K
    49.3K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31680 In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks th… https://www.cve.org/CVERecord?id=CVE-2026-31680

    Post summary

    CVE‑2026‑31680 in the Linux kernel has been patched, with the fix deferring the free of the exclusive flowlabel option until RCU teardown and updating ip6fl_seq_show() behavior.

    0000077
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31680 Linux Kernel IPv6 Flowlabel Use-After-Free via Early Option Free https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31680

    Post summary

    A new Linux kernel IPv6 Flowlabel use‑after‑free vulnerability (CVE‑2026‑31680) is announced with a public link for additional details.

    0000054
    4.0K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more