Stack-based buffer overflow in Linux kernel - CVE-2026-31630
Published: April 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in the AF_RXRPC procfs helpers when formatting socket addresses for procfs output with "%pISpc". A local user can trigger address formatting with a specially crafted IPv6 address representation to cause a denial of service.
The issue occurs because the fixed 50-byte stack buffers are too small for the longest current IPv6-with-port textual form, including certain ISATAP address formats.
Affected software
openEuler
Ubuntu
kernel-tools-debuginfo
bpftool-debuginfo
bpftool
kernel
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-source
kernel-tools
kernel-tools-devel
perf
perf-debuginfo
python2-perf
python2-perf-debuginfo
python3-perf
python3-perf-debuginfo
kernel-headers
linux (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-nvidia-tegra-5.15 (Ubuntu package)
linux-intel-iot-realtime (Ubuntu package)
linux-ibm-5.15 (Ubuntu package)
linux-intel-iotg (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-azure-fde (Ubuntu package)
kernel-extra-modules
How to mitigate CVE-2026-31630
kernel-tools-debuginfo - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
bpftool-debuginfo - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
bpftool - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel-debuginfo - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel-debugsource - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel-devel - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel-source - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel-tools - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel-tools-devel - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
perf - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
perf-debuginfo - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
python2-perf - update to 4.19.90-2605.3.0.0372
python2-perf-debuginfo - update to 4.19.90-2605.3.0.0372
python3-perf - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
python3-perf-debuginfo - addressed in versions 4.19.90-2605.3.0.0372, 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
kernel-headers - addressed in versions 5.10.0-314.0.0.217, 6.6.0-145.1.14.152, 6.6.0-145.3.14.145
linux (Ubuntu package) - addressed in versions 5.15.0.184.155, 5.15.0-184.194, 5.15.0-184.194~20.04.1, 5.15.0.186.166, 5.15.0-186.196, 5.15.0-186.196~20.04.1, 5.15.0.1075.78, 5.15.0-1075.79, 5.15.0.1095.94, 5.15.0-1095.103, 5.15.0.1104.100, 5.15.0-1104.109, 5.15.0.1108.107, 5.15.0-1108.114, 5.15.0.1111.115, 5.15.0-1111.120+fips1, 5.15.0.1112.102, 5.15.0.1112.109, 5.15.0-1112.122, 5.15.0-1112.122+fips1
linux-aws (Ubuntu package) - addressed in versions 5.15.0.186.109, 5.15.0-186.196+fips1, 5.15.0.1106.103, 5.15.0-1106.110, 5.15.0.1107.107, 5.15.0-1107.108, 5.15.0.1112.108, 5.15.0.1112.115, 5.15.0-1112.119, 5.15.0-1112.119+fips1, 5.15.0-1112.119~20.04.1
linux-nvidia-tegra (Ubuntu package) - addressed in versions 5.15.0-1053.53, 5.15.0.1053.55, 5.15.0.1064.64, 5.15.0-1064.66
linux-nvidia-tegra-5.15 (Ubuntu package) - update to 5.15.0-1064.66~20.04.1
linux-intel-iot-realtime (Ubuntu package) - addressed in versions 5.15.0-1104.106, 5.15.0.1104.108, 5.15.0-1107.113~20.04.1
linux-ibm-5.15 (Ubuntu package) - update to 5.15.0-1106.110~20.04.1
linux-intel-iotg (Ubuntu package) - addressed in versions 5.15.0.1107.106, 5.15.0-1107.113
linux-azure (Ubuntu package) - addressed in versions 5.15.0.1109.105, 5.15.0-1109.115, 5.15.0.1117.115, 5.15.0-1117.126
linux-azure-5.15 (Ubuntu package) - addressed in versions 5.15.0-1109.115~20.04.1, 5.15.0-1117.126~20.04.1, 5.15.0-1117.126~20.04.2
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1117.102, 5.15.0-1117.126+fips1
linux-azure-fde (Ubuntu package) - update to 5.15.0-1117.126
kernel-extra-modules - update to 6.6.0-145.3.14.145
External References
Related Security Bulletins
- Stack-based buffer overflow in Linux kernel rxrpc
- openEuler 22.03 LTS SP4 update for kernel
- openEuler 20.03 LTS SP4 update for kernel
- openEuler 24.03 LTS SP3 update for kernel
- openEuler 24.03 LTS SP1 update for kernel
- Ubuntu update for linux-nvidia-tegra-5.15
- Ubuntu update for linux
- Ubuntu update for linux-ibm-5.15
- Ubuntu update for linux-nvidia-tegra
- Ubuntu update for linux-aws
- Ubuntu update for linux-azure-fde
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-5.15
- Ubuntu update for linux-azure-fips
- Ubuntu update for linux-intel-iot-realtime
- Ubuntu update for linux-intel-iotg