IM
IronMonkey Threat Research

CVE-2026-31670 MEDIUM

Published: 2026-04-24 | Last Modified: 2026-07-14 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill events from being created Userspace can create an unlimited number of rfkill events if the system is so configured, while not consuming them from the rfkill file descriptor, causing a potential out of memory situation. Prevent this from bounding the number of pending rfkill events at a "large" number (i.e. 1000) to prevent abuses like this.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7d23bea8b840> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d242455da40> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424536a80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23beb17c00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23bea8b900> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424536240> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23beb17280> Operating System
linux linux_kernel 2.6.31 <built-in method update of dict object at 0x7d23beb14680> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23beb15e80> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d24245349c0> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23bea8bb80> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23beb16bc0> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d24245378c0> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d2424535d80> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d242455d600> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.31:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

References

Notification
Message here