CVE-2026-31415

MEDIUMNVD 5.55.5
EchelonGraph scoreMEDIUM confidence

Score 5.5 from GitHub Security Advisory published 2026-04-13. NVD baseline CVSS 5.5; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
Trending — 4 sources updated this week
5.5EG
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 5.5Exploit: None knownExposed: 0

A fix is available — apply it.

In the Linux kernel, the following vulnerability has been resolved:

ipv6: avoid overflows in ip6_datagram_send_ctl()

Yiming Qian reported :

I believe I found a locally triggerable kernel bug in the IPv6 sendmsg ancillary-data path that can panic the kernel via skb_under_panic() (local DoS).

The core issue is a mismatch between:

  • a 16-bit length accumulator (struct ipv6_txoptions::opt_flen, type
__u16) and
  • a pointer to the *last* provided destination-options header (opt->dst1opt)

when multiple IPV6_DSTOPTS control messages (cmsgs) are provided.

  • include/net/ipv6.h:
  • struct ipv6_txoptions::opt_flen is __u16 (wrap possible).
(lines 291-307, especially 298)
  • net/ipv6/datagram.c:ip6_datagram_send_ctl():
  • Accepts repeated IPV6_DSTOPTS and accumulates into opt_flen
without rejecting duplicates. (lines 909-933)
  • net/ipv6/ip6_output.c:__ip6_append_data():
  • Uses opt->opt_flen + opt->opt_nflen to compute header
sizes/headroom decisions. (lines 1448-1466, especially 1463-1465)
  • net/ipv6/ip6_output.c:__ip6_make_skb():
  • Calls ipv6_push_frag_opts() if opt->opt_flen is non-zero.
(lines 1930-1934)
  • net/ipv6/exthdrs.c:ipv6_push_frag_opts() / ipv6_push_exthdr():
  • Push size comes from ipv6_optlen(opt->dst1opt) (based on the
pointed-to header). (lines 1179-1185 and 1206-1211)
  • opt_flen is a 16-bit accumulator:
  • include/net/ipv6.h:298 defines __u16 opt_flen; /* after fragment hdr */.
  • ip6_datagram_send_ctl() accepts *repeated* IPV6_DSTOPTS cmsgs
and increments opt_flen each time:
  • In net/ipv6/datagram.c:909-933, for IPV6_DSTOPTS:
  • It computes len = ((hdr->hdrlen + 1) << 3);
  • It checks CAP_NET_RAW using ns_capable(net->user_ns,
CAP_NET_RAW). (line 922)
  • Then it does:
  • opt->opt_flen += len; (line 927)
  • opt->dst1opt = hdr; (line 928)

There is no duplicate rejection here (unlike the legacy IPV6_2292DSTOPTS path which rejects duplicates at net/ipv6/datagram.c:901-904).

If enough large IPV6_DSTOPTS cmsgs are provided, opt_flen wraps while dst1opt still points to a large (2048-byte) destination-options header.

In the attached PoC (poc.c):

  • 32 cmsgs with hdrlen=255 => len = (255+1)*8 = 2048
  • 1 cmsg with hdrlen=0 => len = 8
  • Total increment: 32*2048 + 8 = 65544, so (__u16)opt_flen == 8
  • The last cmsg is 2048 bytes, so dst1opt points to a 2048-byte header.
  • The transmit path sizes headers using the wrapped opt_flen:
  • In net/ipv6/ip6_output.c:1463-1465:
  • headersize = sizeof(struct ipv6hdr) + (opt ? opt->opt_flen +
opt->opt_nflen : 0) + ...;

With wrapped opt_flen, headersize/headroom decisions underestimate what will be pushed later.

  • When building the final skb, the actual push length comes from
dst1opt and is not limited by wrapped opt_flen:
  • In net/ipv6/ip6_output.c:1930-1934:
  • if (opt->opt_flen) proto = ipv6_push_frag_opts(skb, opt, proto);
  • In net/ipv6/exthdrs.c:1206-1211, ipv6_push_frag_opts() pushes
dst1opt via ipv6_push_exthdr().
  • In net/ipv6/exthdrs.c:1179-1184, ipv6_push_exthdr() does:
  • skb_push(skb, ipv6_optlen(opt));
  • memcpy(h, opt, ipv6_optlen(opt));

With insufficient headroom, skb_push() underflows and triggers skb_under_panic() -> BUG():

  • net/core/skbuff.c:2669-2675 (skb_push() calls skb_under_panic())
  • net/core/skbuff.c:207-214 (skb_panic() ends in BUG())
  • The IPV6_DSTOPTS cmsg path requires CAP_NET_RAW in the target
netns user namespace (ns_capable(net->user_ns, CAP_NET_RAW)).
  • Root (or any task with CAP_NET_RAW) can trigger this without user
namespaces.
  • An unprivileged uid=1000 user can trigger this if unprivileged
user namespaces are enabled and it can create a userns+netns to obtain namespaced CAP_NET_RAW (the attached PoC does this).
  • Local denial of service: kernel BUG/panic (system crash).
  • ---truncated---

CVSS v3
5.5
EG Score
5.5(medium)
EG Risk
29(Track)
EG Risk 29/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity55% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
2%
KEV
Not listed

Published

April 13, 2026

Last Modified

September 8, 2026

Advisory Details (10)

Auto-updated Jul 19, 2026
⚠️ Active exploitation confirmed. No patch confirmed yet.
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/9ed81d692758dfb9471d7799b24bfa7a08224c31
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/872b74900d5daa37067ac676d9001bb929fc6a2a
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/63fda74885555e6bd1623b5d811feec998740ba4
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/5e4ee5dbea134e9257f205e31a96040bed71e83f
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4e453375561fc60820e6b9d8ebeb6b3ee177d42e
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4082f9984a694829153115d28c956a3534f52f29
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/2dbfb003bbf3fc0e94f07efefab0ebcf83029a2a
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/0bdaf54d3aaddfe8df29371260fa8d4939b4fd6f

Vendor Advisories for CVE-2026-31415(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Patch Availability(27)

Vendor / EcosystemFixed in / PatchReleasedSource
ubuntulinux-virtual-6.8 (6.8.0-136.136) @ noble2026-09-08ubuntu
ubuntulinux-tools-gcp-fips-6.8 (6.8.0-1064.72+fips1) @ noble2026-09-08ubuntu
ubuntulinux-xilinx-zynqmp-tools-5.15.0-1075 (5.15.0-1075.79) @ jammy2026-09-08ubuntu
ubuntulinux-tools-nvidia-tegra-rt-5.15 (5.15.0.1064.66~20.04.1) @ focal2026-09-08ubuntu
ubuntulinux-tools-oracle-lts-24.04 (6.8.0-1058.61) @ noble2026-09-08ubuntu
ubuntulinux-tools-oracle-edge (6.8.0-1058.61~22.04.1) @ jammy2026-09-08ubuntu
ubuntulinux-tools-nvidia-lowlatency-64k-6.8 (6.8.0-1059.62.1) @ noble2026-09-08ubuntu
ubuntulinux-tools-nvidia-lowlatency-5.15 (5.15.0.1107.107) @ jammy2026-09-08ubuntu
ubuntulinux-tools-nvidia-tegra-rt-5.15 (5.15.0.1064.64) @ jammy2026-09-08ubuntu
ubuntulinux-tools-ibm-edge (5.15.0.1106.110~20.04.1) @ focal2026-09-08ubuntu
ubuntulinux-tools-aws-lts-24.04 (6.8.0-1061.64+1) @ noble2026-09-08ubuntu
ubuntulinux-tools-azure-edge (6.8.0-1063.71~22.04.1) @ jammy2026-09-08ubuntu
ubuntulinux-tools-azure-fde-lts-24.04 (6.8.0-1062.69) @ noble2026-09-08ubuntu
ubuntulinux-tools-azure-fips-6.8 (6.8.0-1063.71+fips2) @ noble2026-09-08ubuntu
ubuntulinux-tools-azure-fde-6.8 (6.8.0-1062.69~22.04.1) @ jammy2026-09-08ubuntu
ubuntulinux-tools-oracle-lts-22.04 (5.15.0.1109.105) @ jammy2026-09-08ubuntu
ubuntulinux-tools-azure-fde-lts-22.04 (5.15.0.1117.126) @ jammy2026-09-08ubuntu
ubuntulinux-tools-raspi-realtime-6.8 (6.8.0-2050.52) @ noble2026-09-08ubuntu
ubuntulinux-tools-aws-fips-6.8 (6.8.0-1061.64+fips1) @ noble2026-09-08ubuntu
ubuntulinux-xilinx-zynqmp (6.8.0.1033.34) @ noble2026-09-08ubuntu
ubuntulinux-virtual-hwe-22.04-edge (6.8.0-136.136~22.04.1) @ jammy2026-09-08ubuntu
ubuntulinux-tools-oracle-edge (5.15.0.1109.115~20.04.1) @ focal2026-09-08ubuntu
ubuntulinux-tools-azure-fips-5.15 (5.15.0.1117.102) @ jammy2026-09-08ubuntu
ubuntulinux-tools-intel-iot-realtime-5.15 (5.15.0.1104.108) @ jammy2026-09-08ubuntu
ubuntulinux-tools-intel-iotg-5.15 (5.15.0.1107.106) @ jammy2026-09-08ubuntu
ubuntulinux-tools-gcp-edge (5.15.0.1112.122~20.04.1) @ focal2026-09-08ubuntu
linuxKernel @ 5.10.253osv

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Affected Packages

(5 across 4 ecosystems)
Debian:11(2)
PackageVulnerable rangeFixed inDependents
linux5.10.103-1 ... 5.10.92-2 (53 versions)5.10.257-1
linux-6.16.1.106-3~deb11u1 ... 6.1.164-1~deb11u1 (16 versions)6.1.170-1~deb11u1
Debian:12(1)
PackageVulnerable rangeFixed inDependents
linux6.1.106-1 ... 6.1.99-1 (48 versions)6.1.170-1
Debian:13(1)
PackageVulnerable rangeFixed inDependents
linux6.12.38-1 ... 6.12.85-1~bpo12+1 (17 versions)6.12.85-1
Debian:14(1)
PackageVulnerable rangeFixed inDependents
linux6.12.100-1 ... 6.19~rc8-1~exp1 (125 versions)6.19.12-1

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

All Vendor Advisories

(25)

Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.

Data Freshness Timeline

(refreshed 7× in last 7d / 28× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

Showing the most recent 100 of 185 total refreshes for this CVE.

  1. 2026-09-13 16:47 UTCEPSS rescore
  2. 2026-09-11 14:52 UTCEPSS rescore
  3. 2026-09-10 09:34 UTCEPSS rescore
  4. 2026-09-08 22:00 UTCEPSS rescore
  5. 2026-09-08 09:12 UTCEG score recompute
  6. 2026-09-08 09:12 UTCVendor advisory
  7. 2026-09-08 09:11 UTCGHSA enrichment
  8. 2026-09-06 13:47 UTCEPSS rescore
  9. 2026-09-06 13:47 UTCEPSS rescore
  10. 2026-09-04 05:06 UTCEPSS rescore
  11. 2026-09-02 05:28 UTCOSV refresh
  12. 2026-09-01 13:53 UTCEPSS rescore
  13. 2026-09-01 04:39 UTCEPSS rescore
  14. 2026-09-01 04:39 UTCEPSS rescore
  15. 2026-08-30 19:17 UTCEPSS rescore
  16. 2026-08-28 21:41 UTCEPSS rescore
  17. 2026-08-27 14:25 UTCEPSS rescore
  18. 2026-08-26 14:46 UTCEPSS rescore
  19. 2026-08-25 13:49 UTCEPSS rescore
  20. 2026-08-24 14:17 UTCEPSS rescore
  21. 2026-08-23 00:19 UTCEPSS rescore
  22. 2026-08-21 23:49 UTCEPSS rescore
  23. 2026-08-20 22:55 UTCEPSS rescore
  24. 2026-08-20 22:55 UTCEPSS rescore
  25. 2026-08-19 17:03 UTCEPSS rescore
Show 75 more
  1. 2026-08-18 13:48 UTCEPSS rescore
  2. 2026-08-17 13:47 UTCEPSS rescore
  3. 2026-08-16 14:56 UTCEPSS rescore
  4. 2026-08-16 06:55 UTCEG score recompute
  5. 2026-08-16 06:55 UTCVendor advisory
  6. 2026-08-16 06:55 UTCGHSA enrichment
  7. 2026-08-16 02:14 UTCEPSS rescore
  8. 2026-08-15 01:30 UTCEPSS rescore
  9. 2026-08-14 04:57 UTCEG score recompute
  10. 2026-08-14 04:57 UTCVendor advisory
  11. 2026-08-14 04:57 UTCGHSA enrichment
  12. 2026-08-13 22:00 UTCEPSS rescore
  13. 2026-08-12 23:18 UTCEG score recompute
  14. 2026-08-12 23:18 UTCVendor advisory
  15. 2026-08-12 23:18 UTCGHSA enrichment
  16. 2026-08-12 13:50 UTCEPSS rescore
  17. 2026-08-12 01:08 UTCEG score recompute
  18. 2026-08-12 01:08 UTCVendor advisory
  19. 2026-08-12 01:07 UTCGHSA enrichment
  20. 2026-08-11 02:52 UTCEG score recompute
  21. 2026-08-11 02:52 UTCVendor advisory
  22. 2026-08-11 02:52 UTCGHSA enrichment
  23. 2026-08-11 00:00 UTCEPSS rescore
  24. 2026-08-10 02:30 UTCEG score recompute
  25. 2026-08-10 02:30 UTCVendor advisory
  26. 2026-08-10 02:30 UTCGHSA enrichment
  27. 2026-08-09 13:46 UTCEPSS rescore
  28. 2026-08-09 04:20 UTCEG score recompute
  29. 2026-08-09 04:20 UTCVendor advisory
  30. 2026-08-09 04:20 UTCGHSA enrichment
  31. 2026-08-08 16:37 UTCEPSS rescore
  32. 2026-08-07 14:00 UTCEG score recompute
  33. 2026-08-07 14:00 UTCVendor advisory
  34. 2026-08-07 14:00 UTCGHSA enrichment
  35. 2026-08-06 13:46 UTCEPSS rescore
  36. 2026-08-05 23:35 UTCEG score recompute
  37. 2026-08-05 23:35 UTCVendor advisory
  38. 2026-08-05 23:35 UTCGHSA enrichment
  39. 2026-08-05 19:17 UTCEPSS rescore
  40. 2026-08-04 15:10 UTCEPSS rescore
  41. 2026-08-03 21:49 UTCEG score recompute
  42. 2026-08-03 21:49 UTCVendor advisory
  43. 2026-08-03 21:49 UTCGHSA enrichment
  44. 2026-08-03 10:36 UTCEPSS rescore
  45. 2026-08-02 13:34 UTCEG score recompute
  46. 2026-08-02 13:34 UTCVendor advisory
  47. 2026-08-02 13:34 UTCGHSA enrichment
  48. 2026-08-02 02:27 UTCEPSS rescore
  49. 2026-08-01 04:16 UTCEPSS rescore
  50. 2026-07-30 16:27 UTCEPSS rescore
  51. 2026-07-28 15:36 UTCEPSS rescore
  52. 2026-07-25 14:18 UTCEPSS rescore
  53. 2026-07-25 14:17 UTCEPSS rescore
  54. 2026-07-24 14:17 UTCEPSS rescore
  55. 2026-07-23 14:18 UTCEPSS rescore
  56. 2026-07-23 14:18 UTCEPSS rescore
  57. 2026-07-23 03:08 UTCEG score recompute
  58. 2026-07-22 14:08 UTCEPSS rescore
  59. 2026-07-22 14:08 UTCEPSS rescore
  60. 2026-07-21 15:24 UTCEPSS rescore
  61. 2026-07-21 15:24 UTCEPSS rescore
  62. 2026-07-20 17:08 UTCEPSS rescore
  63. 2026-07-20 17:08 UTCEPSS rescore
  64. 2026-07-20 12:02 UTCOSV refresh
  65. 2026-07-19 14:31 UTCEPSS rescore
  66. 2026-07-19 14:31 UTCEPSS rescore
  67. 2026-07-18 10:04 UTCEPSS rescore
  68. 2026-07-18 10:04 UTCEPSS rescore
  69. 2026-07-16 17:03 UTCEPSS rescore
  70. 2026-07-16 17:03 UTCEPSS rescore
  71. 2026-07-15 16:57 UTCEPSS rescore
  72. 2026-07-15 16:57 UTCEPSS rescore
  73. 2026-07-14 13:19 UTCNVD updateCVSS v3 → 5.5 · severity → MEDIUM
  74. 2026-07-14 13:11 UTCMITRE cvelistV5
  75. 2026-07-13 22:30 UTCEPSS rescore

Frequently asked(5)

What is CVE-2026-31415?
CVE-2026-31415 is a medium vulnerability published on April 13, 2026. In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6datagramsend_ctl() Yiming Qian reported : <quote> I believe I found a locally triggerable kernel bug in the IPv6 sendmsg ancillary-data path that can panic the kernel via skbunderpanic() (local DoS). The…
When was CVE-2026-31415 disclosed?
CVE-2026-31415 was first published in the National Vulnerability Database on April 13, 2026, with the most recent update on September 8, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-31415 actively exploited?
CVE-2026-31415 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 98.3% of all scored CVEs.
What is the CVSS score of CVE-2026-31415?
CVE-2026-31415 has a CVSS v3 base score of 5.5 (NVD).
How do I remediate CVE-2026-31415?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-31415, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-31415

Explore →

Is Your Infrastructure Affected by CVE-2026-31415?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.