CVE-2026-31694PoC(linux / linux_kernel)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the dirent into a single page-cache page. The existing logic only checks whether the dirent fits in the remaining space of the current page and advances to a fresh page if not. It never checks whether the dirent itself exceeds PAGE_SIZE. As a result, a malicious FUSE server can return a dirent with namelen=4095, producing a serialized record size of 4120 bytes. On 4 KiB page systems this causes memcpy() to overflow the cache page by 24 bytes into the following kernel page. Reject dirents that cannot fit in a single page before copying them into the readdir cache.

4.3/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 22 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 19 signals
  • General: 5 classified signals
  • Disclosure: 5 classified signals
  • Peaked 6d ago at 5 mentions (2026-07-03); latest day: 1
  • 22 total mentions across 10 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline22 mentions / 10d
01345Mentions · 2026-05-12: 1Mentions · 2026-05-20: 1Mentions · 2026-07-01: 2Mentions · 2026-07-03: 5Mentions · 2026-07-06: 1Mentions · 2026-07-10: 4Mentions · 2026-07-11: 2Mentions · 2026-07-21: 4Mentions · 2026-08-02: 1Mentions · 2026-09-14: 1PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-07-01: 2PoC Mentioned / Linked · 2026-07-03: 2PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-10: 2PoC Mentioned / Linked · 2026-07-11: 1PoC Mentioned / Linked · 2026-07-21: 1Exploit Tool / Code · 2026-07-01: 2Exploit Tool / Code · 2026-07-03: 2Exploit Tool / Code · 2026-07-06: 1Exploit Tool / Code · 2026-07-10: 2Exploit Tool / Code · 2026-07-21: 1Patch / Workaround · 2026-07-03: 4Patch / Workaround · 2026-07-10: 2Patch / Workaround · 2026-07-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-03: 4Technical Details · 2026-07-06: 1Technical Details · 2026-07-10: 4Technical Details · 2026-07-11: 2Technical Details · 2026-07-21: 3Technical Details · 2026-08-02: 1Technical Details · 2026-09-14: 105-1205-2007-0107-0307-0607-1007-1107-2108-0209-14
Signal classification5 categories
PoC
836.4%
General
522.7%
Disclosure
522.7%
Patch
29.1%
Exploit
29.1%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-05-121
PoC1
2026-05-201
General1
2026-07-012
PoC2
2026-07-035
General1Patch2PoC2
2026-07-061
Exploit1
2026-07-104
Disclosure1General1PoC2
2026-07-112
Disclosure1PoC1
2026-07-214
Disclosure2Exploit1General1
2026-08-021
General1
2026-09-141
Disclosure1
Full discourse20 posts
  • portbuster@portbuster1337
    Exploit

    Added 4 new LPE exploits to lpe-toolkit: - PEdit COW CVE-2026-46331 - DirtyClone CVE-2026-43503 - Bad Epoll CVE-2026-46242 - FUSE OOB CVE-2026-31694 https://github.com/portbuster1337/lpe-toolkit

    Post summary

    Four new low‑privilege escape exploits for CVE‑2026‑46331, CVE‑2026‑43503, CVE‑2026‑46242, and CVE‑2026‑31694 have been added to the lpe‑toolkit, with a GitHub link pointing to the exploit code.

    465129519715.8K
    289 followersView on X
  • bynario@bynar_io
    PoC

    Now that Canonical has fully patched CVE-2026-31694, we're sharing our code (along with a lil demo) for the FUSE LPE 🐧 Source @ https://github.com/BynarIO/pocs/tree/main/linux/cve-2026-31694 https://t.co/uE9qi6gUAw

    Post summary

    The author shares a Proof of Concept code and demo for the FUSE Local Privilege Escalation CVE‑2026‑31694, noting that Canonical has patched it.

    73221056112.7K
    370 followersView on X
  • bynario@bynar_io
    PoC

    Continuing the series: @sam4k1 digs into CVE-2026-31694, a page cache overflow in the kernel's FUSE subsystem that our pipeline surfaced and validated with an LPE on Ubuntu 26.04 using Opus 4.6. https://bynar.io/blog/discovery-validation-in-the-linux-kernel-part-2-fuse-page-cache-overflow

    Post summary

    The post confirms a functional proof‑of‑concept for CVE-2026-31694, demonstrating a local privilege escalation on Ubuntu 26.04 via a page cache overflow in FUSE, with details available in an associated blog post.

    023163427.4K
    253 followersView on X
  • bynario@bynar_io
    General

    To wrap-up the series, @sam4k1 puts local models running on a Mac Studio head-to-head with Opus 4.6 on the kernel bugs, CVE-2026-31532 & CVE-2026-31694, from parts 1 & 2. https://bynar.io/blog/discovery-validation-in-the-linux-kernel-part-3-local-vs-frontier-models/

    Post summary

    The tweet simply refers to two Linux kernel CVEs and directs readers to a blog post for more information, but provides no concrete details, PoCs, or exploitation evidence.

    062323411.4K
    253 followersView on X
  • dbugs@ptdbugs
    PoC

    Linux Kernel FUSE Page Cache Out-of-Bounds Write CVE: CVE-2026-31694 PT ID: PT-2026-36324 Vendor: Linux Product: Linux CVSS: 7.8 Credits: n/a Description: An issue exists in the "fuse add dirent to cache()" function where the system computes a serialized directory entry (dirent) size based on the server-controlled "namelen" field and copies it into a single page-cache page. The logic fails to verify if the dirent itself exceeds the "PAGE SIZE", only checking if it fits in the remaining space of the current page. Consequently, a malicious FUSE server can provide a dirent with "namelen" set to 4095, resulting in a serialized record size of 4120 bytes. On systems with 4 KiB pages, this leads to a "memcpy()" operation that overflows the cache page by 24 bytes into the subsequent kernel page. Exploitation requires a vulnerable Linux kernel and the ability for a local low-privileged attacker to mount or interact with a malicious FUSE filesystem. Successful exploitation results in an out-of-bounds kernel memory write, potentially leading to kernel memory corruption, local privilege escalation to root, denial of service, or arbitrary code execution in kernel context. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-31694 • https://git.kernel.org/stable/c/3059f9abe7f1ba8fddf3c86c5faa1eeacf07e7d4 PoC/Exploit: • https://github.com/0xCyberstan/CVE-2026-31694-POC • https://cyberstan.co.uk/fuse-readdir-oob/ #dbugs_vuln

    Post summary

    The entry discloses CVE‑2026‑31694, a kernel out‑of‑bounds write in FUSE, and provides detailed technical info along with public PoC code and links.

    08027102.3K
    3.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Public PoC and full details are out for CVE-2026-31694, a Linux kernel FUSE page cache overflow that gives local privilege escalation to root. Patch now. #LinuxKernel #FUSE #CVE202631694 #PrivilegeEscalation #InfoSec http://securityonline.info/linux-kernel-fuse-cve-2026-31694/

    Post summary

    A public PoC for CVE‑2026‑31694, a Linux kernel FUSE page cache overflow enabling local privilege escalation, has been released along with a patch.

    1402041.5K
    12.9K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #Kernel_Security 1⃣ CVE-2026-36425: OPSWAT AppRemover Arbitrary Process Termination https://github.com/redteamfortress/CVE-2026-36425 2⃣ CVE-2026-31694: Unprivileged root via an out-of-bounds write in the FUSE readdir cache https://cyberstan.co.uk/fuse-readdir-oob // http://www.cyberpocket.org

    Post summary

    The post lists two kernel CVEs, links to GitHub PoCs, and a write‑up, but makes no claim of active exploitation or patches.

    04097493
    3.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Linux kernel'de keşfedilen CVE-2026-31694, FUSE bileşenindeki Out-of-Bounds Write güvenlik açığıdır. Uygun koşullarda Yerel Yetki Yükseltme (LPE) amacıyla kullanılabiliyor. Bu açık yamalandı. PoC (bynario tarafından): https://github.com/BynarIO/pocs/tree/main/linux/cve-2026-31694 https://t.co/acC5f7YaNX

    Post summary

    The text announces CVE-2026-31694 as an Out‑of‑Bounds Write in Linux kernel’s FUSE that allows local privilege escalation, provides a PoC reference, and notes that the patch has been released.

    03051542
    2.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Linux Kernel FUSE の脆弱性 CVE-2026-31694:root 権限奪取の可能性 https://iototsecnews.jp/2026/07/10/linux-kernel-fuse-vulnerability-lets-attackers-gain-root-privileges/ 脆弱性 CVE-2026-31694 は、 Kernel の FUSE サブシステムにおける、ディレクトリ・エントリのサイズ・チェックの不備に起因します。この欠陥を突く悪意のサーバが、1 ページの容量を超える大きなデータを返した際に、事前の確認がないままキャッシュ・ページへコピーされるため、隣接するメモリ領域へデータがあふれ出してしまいます。このメモリ破損により、SUID バイナリのデータが書き換えられ、結果としてローカルの攻撃者に root 権限を奪取される危険性があります。ページサイズが 4 KiB のシステムにおいて、サイズ計算の不備と境界チェックの欠如が重なったことが深刻な問題に繋がっています。ご利用のチームは、ご注意ください。 #CVE202631694 #FUSE #Kernel #Linux #Vulnerability

    Post summary

    The article discloses a newly identified FUSE kernel vulnerability (CVE-2026-31694) that can cause memory corruption and enable local privilege escalation; it warns teams to be alert but does not provide patch or exploit details.

    03010294
    500 followersView on X
  • OS開発者@hacker_infra
    Patch

    Ubuntu lsmod | grep fuse モジュール読み込んでなければ緩和策 cat > /etc/modprobe.d/disable-fuse.conf <<'EOF' install fuse /bin/true EOF https://ubuntu.com/security/CVE-2026-31694

    Post summary

    The post provides a mitigation workaround to disable fuse on Ubuntu, referencing the CVE-2026-31694 security advisory.

    00040776
    2.9K followersView on X
  • moton@moton
    General

    CVE-2026-31694: Linux Kernel FUSE Privilege Escalation - https://securityonline.info/linux-kernel-fuse-cve-2026-31694/

    Post summary

    The text references CVE-2026-31694 as a Linux Kernel FUSE privilege escalation and links to an external article, but provides no evidence of PoC, exploitation, patch, or active attacks.

    01020142
    661 followersView on X
  • VulnTracker@vuln_tracker
    PoC

    A public PoC changes the game. CVE-2026-31694, a Linux kernel FUSE page cache overflow, now has a publicly available PoC demonstrating local privilege escalation to root. If your environment is affected, now is the time to prioritize patching before attackers start weaponizing it. #Linux #CyberSecurity #InfoSec http://vulntracker.io

    Post summary

    A public proof‑of‑concept now demonstrates that CVE‑2026‑31694, a Linux kernel FUSE page cache overflow, can lead to local privilege escalation, and affected systems should patch promptly to avoid future exploitation.

    0101089
    681 followersView on X
  • -ENOMEM@masami256
    PoC

    0xCyberstan/CVE-2026-31694-POC: Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): . https://github.com/0xCyberstan/CVE-2026-31694-POC

    Post summary

    The post announces a PoC repository on GitHub for CVE-2026-31694, detailing an out-of-bounds write in the Linux kernel FUSE readdir cache.

    00110648
    2.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-31694. Source: X search for PoC exploit 2026 Posted: 2026-07-01T10:53:44.000Z Likes: 27

    Post summary

    The tweet merely references CVE‑2026‑31694 without giving any technical, exploit, patch, or active‑use information.

    1000040
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Vendor v7.8. Source: X search for PoC exploit 2026 Posted: 2026-07-01T10:53:44.000Z Likes: 27 Linux Kernel FUSE Page Cache Out-of-Bounds Write CVE: CVE-2026-31694 PT ID: PT-2026-36324 Vendor: Linux Product: Linux CVSS: 7.8 Credits: n/a Description: An issue exists in…

    Post summary

    The post announces a Linux Kernel FUSE out‑of‑bounds write vulnerability (CVE‑2026‑31694) with a CVSS score of 7.8, but provides no PoC, exploit, or patch information.

    1000042
    326 followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-31694: A public PoC has been released for a Linux kernel FUSE page cache overflow vulnerability that could allow local privilege escalation to root. 🔗 https://github.com/BynarIO/pocs/tree/main/linux/cve-2026-31694 #CyberSecurity #CVE #Linux #ThreatWire https://t.co/508xiDCuEC

    Post summary

    The tweet announces a public PoC for CVE-2026-31694, a Linux kernel FUSE page cache overflow that can lead to local privilege escalation, with exploit code available on GitHub; no patches, active exploitation, or false‑positive claims are mentioned.

    00010128
    69 followersView on X
  • sam4k@sam4k1
    General

    @thingwhere @bynar_io Hey 👋 Weirdly for me it shows EL9 as "Not affected" on that page, either way while the root cause for CVE-2026-31694 was introduced in v4.20, it is only reachable due to a second commit introduced in v6.16. (1/2)

    Post summary

    The tweet notes that CVE-2026-31694 does not affect EL9, explains that its root cause appears in v4.20 but is only exploitable through a second commit in v6.16.

    10000106
    2.7K followersView on X
  • cybrmonk@cybr_monk
    Disclosure

    CVE-2026-31694: FUSE Dirent Overflow Lets Attackers Corrupt Kernel Memory on Live Systems https://cybrmonk.com/blog/cve-2026-31694-fuse-dirent-overflow-lets-attackers-corrupt-kernel-memory-on-live-systems #cybersecurity #threatintelligence https://t.co/8ebCMe8ms8

    Post summary

    The text is a tweet announcing CVE-2026-31694, describing a FUSE dirent overflow vulnerability that can corrupt kernel memory on live systems, with a link to a blog post for further details but no mention of PoC, exploit tools, patches, or active exploitation.

    0000036
    47 followersView on X
  • Komodo Cyber Security@Komodosec
    General

    Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) https://cyberstan.co.uk/fuse-readdir-oob/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces CVE-2026-31694, describing an out-of-bounds write in the FUSE readdir cache that could allow unprivileged users to gain root, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000074
    1.5K followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    A critical vulnerability in the Linux kernel's FUSE subsystem (CVE-2026-31694) allows local attackers to escalate privileges to root by exploiting improper validation in directory entry caching. Administrators should update their systems promptly to mitigate this risk. #LinuxKernel #FUSE #CVE202631694 #SecurityVulnerability #PrivilegeEscalation #CyberSecurity https://thedailytechfeed.com/linux-kernel-fuse-vulnerability-grants-root-access-to-attackers/

    Post summary

    A critical FUSE subsystem flaw in the Linux kernel (CVE-2026-31694) allows local attackers to gain root privileges; administrators are urged to apply updates promptly.

    0000076
    506 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more