Out-of-bounds read in Linux kernel - CVE-2026-31464
Published: April 24, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ibmvfc_alloc_targets() when processing a discover targets MAD response from a VIO server. A remote attacker can return a crafted num_written value exceeding max_targets to disclose sensitive information.
The out-of-bounds data is embedded in Implicit Logout and PLOGI MADs sent back to the VIO server.
How to mitigate CVE-2026-31464
Sources
- https://git.kernel.org/stable/c/394a1cac3c12fdd7d77f19ccfd222ab5ff87ef89
- https://git.kernel.org/stable/c/4ed727e35b0ab17d3eeeb1e8023768396e2be161
- https://git.kernel.org/stable/c/61d099ac4a7a8fb11ebdb6e2ec8d77f38e77362f
- https://git.kernel.org/stable/c/786f10b1966e485046839f992e89f2c18cbd1983
- https://git.kernel.org/stable/c/a007246cb6c9ebdc93dafbf63cc2d43d98f402cc
- https://git.kernel.org/stable/c/bae4df0a643fa7f84663473aa3082a9c2ed139db
- https://git.kernel.org/stable/c/d1466bf991b2343cf2ba8336e440c8faf3cbb780
- https://git.kernel.org/stable/c/d842348f8a00d5b1d7358f207eb34ffcf5b16df3