Improper access control in Linux kernel - CVE-2026-31692
Published: April 30, 2026
Vulnerability details
The vulnerability allows a local user to create interfaces in arbitrary network namespaces.
The vulnerability exists due to improper access control in rtnl_newlink() when creating paired devices with a peer network namespace. A local user can create veth, vxcan, or netkit interfaces to create interfaces in arbitrary network namespaces.
Exploitation requires a user namespace.
Affected software
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
kernel (Red Hat package)
kernel-rt (Red Hat package)
How to mitigate CVE-2026-31692
kernel (Red Hat package) - update to 4.18.0-553.150.1.el8_10
kernel-rt (Red Hat package) - update to 4.18.0-553.150.1.rt7.491.el8_10