IM
IronMonkey Threat Research

CVE-2026-31671 MEDIUM

Published: 2026-04-24 | Last Modified: 2026-07-14 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct xfrm_user_report is a __u8 proto field followed by a struct xfrm_selector which means there is three "empty" bytes of padding, but the padding is never zeroed before copying to userspace. Fix that up by zeroing the structure before setting individual member variables.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en CWE-401

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7d242450afc0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23afb19640> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24245082c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23afb1ba00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424509300> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424508900> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24245085c0> Operating System
linux linux_kernel 2.6.19 <built-in method update of dict object at 0x7d242450b480> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23afb18f80> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d242450a900> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d239fbe8ec0> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d2424509380> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d2424509400> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23a59c8cc0> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23a59c83c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.19:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

References

Notification
Message here