PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31405 Linux CVE debrief

CVE-2026-31405 is a critical Linux kernel media/dvb-net memory-safety issue. Network-controlled ULE extension data can produce htype values from 0-255, but the handler tables are sized for valid indices 0-254. When htype is 255, the kernel can read past the end of the function-pointer table, and the out-of-bounds value may be invoked as a function pointer. The published fix adds a bounds check and discards out-of-range SNDUs. NVD lists the issue as analyzed, with CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and provides affected Linux kernel version ranges through multiple stable branches.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Linux kernel maintainers, distro security teams, embedded device vendors, and operators running kernels that include the dvb-net media code path should care, especially where DVB networking features are enabled or reachable through untrusted input. Security responders should treat it as a critical kernel memory-safety bug with a public patch available.

Technical summary

In handle_one_ule_extension(), the ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables are declared with 255 elements, so valid indices are 0-254. The handler index htype is derived from network-controlled data as (ule_sndu_type & 0x00FF), which permits 255. That mismatch allows an out-of-bounds read from a function-pointer table. The fix adds a size check before either table is accessed; values outside the table bounds now cause the SNDU to be discarded. The weakness is categorized by NVD as CWE-125.

Defensive priority

High. This is a critical kernel issue with network-controlled input and vendor patches already available. Prioritize patching affected Linux kernel builds, especially systems that include the dvb-net path and are exposed to untrusted DVB traffic or inputs. Use the NVD version ranges to confirm whether a specific kernel build is affected.

Recommended defensive actions

  • Apply the vendor or stable kernel patches referenced by NVD.
  • Verify whether your kernel build falls within the affected ranges listed by NVD before and after backporting.
  • If DVB networking is not required, disable or remove the relevant kernel feature set where operationally feasible.
  • Rebuild and redeploy any custom or embedded kernels that may not receive automatic stable updates.
  • Track the official Linux kernel release notes and distro advisories for backported fixes.
  • Use the CVE published date (2026-04-06) and NVD modification date (2026-05-20) to align remediation and verification timelines.

Evidence notes

All statements are based on the supplied CVE description and NVD metadata. The issue was published on 2026-04-06 and last modified in NVD on 2026-05-20. NVD marks the CVE as analyzed, lists CVSS 3.1 9.8/CRITICAL, and includes patch references from git.kernel.org. No KEV entry was provided in the source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31405 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31405

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31405 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31405

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/145e50c2c700fa52b840df7bab206043997dd18e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1a6da3dbb9985d00743073a1cc1f96e59f5abc30

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/24d87712727a5017ad142d63940589a36cd25647

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/29ef43ceb121d67b87f4cbb08439e4e9e732eff8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8bde543d2a5f935ba2a6a6325a2e02f8a9256fbe

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b2bd2ee73b697c177157bba534e1b1064c2e66a0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e51238718217c4abdb3ccc3b0c0cde265c7ec629

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.