PatchSiren cyber security CVE debrief
CVE-2026-31405 Linux CVE debrief
CVE-2026-31405 is a critical Linux kernel media/dvb-net memory-safety issue. Network-controlled ULE extension data can produce htype values from 0-255, but the handler tables are sized for valid indices 0-254. When htype is 255, the kernel can read past the end of the function-pointer table, and the out-of-bounds value may be invoked as a function pointer. The published fix adds a bounds check and discards out-of-range SNDUs. NVD lists the issue as analyzed, with CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and provides affected Linux kernel version ranges through multiple stable branches.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Linux kernel maintainers, distro security teams, embedded device vendors, and operators running kernels that include the dvb-net media code path should care, especially where DVB networking features are enabled or reachable through untrusted input. Security responders should treat it as a critical kernel memory-safety bug with a public patch available.
Technical summary
In handle_one_ule_extension(), the ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables are declared with 255 elements, so valid indices are 0-254. The handler index htype is derived from network-controlled data as (ule_sndu_type & 0x00FF), which permits 255. That mismatch allows an out-of-bounds read from a function-pointer table. The fix adds a size check before either table is accessed; values outside the table bounds now cause the SNDU to be discarded. The weakness is categorized by NVD as CWE-125.
Defensive priority
High. This is a critical kernel issue with network-controlled input and vendor patches already available. Prioritize patching affected Linux kernel builds, especially systems that include the dvb-net path and are exposed to untrusted DVB traffic or inputs. Use the NVD version ranges to confirm whether a specific kernel build is affected.
Recommended defensive actions
- Apply the vendor or stable kernel patches referenced by NVD.
- Verify whether your kernel build falls within the affected ranges listed by NVD before and after backporting.
- If DVB networking is not required, disable or remove the relevant kernel feature set where operationally feasible.
- Rebuild and redeploy any custom or embedded kernels that may not receive automatic stable updates.
- Track the official Linux kernel release notes and distro advisories for backported fixes.
- Use the CVE published date (2026-04-06) and NVD modification date (2026-05-20) to align remediation and verification timelines.
Evidence notes
All statements are based on the supplied CVE description and NVD metadata. The issue was published on 2026-04-06 and last modified in NVD on 2026-05-20. NVD marks the CVE as analyzed, lists CVSS 3.1 9.8/CRITICAL, and includes patch references from git.kernel.org. No KEV entry was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31405 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31405
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31405 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31405
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/145e50c2c700fa52b840df7bab206043997dd18e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1a6da3dbb9985d00743073a1cc1f96e59f5abc30
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/24d87712727a5017ad142d63940589a36cd25647
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/29ef43ceb121d67b87f4cbb08439e4e9e732eff8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8bde543d2a5f935ba2a6a6325a2e02f8a9256fbe
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b2bd2ee73b697c177157bba534e1b1064c2e66a0
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e51238718217c4abdb3ccc3b0c0cde265c7ec629
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.