CVE-2026-31415

MEDIUMNVD 5.55.5
EchelonGraph scoreMEDIUM confidence

Score 5.5 from GitHub Security Advisory published 2026-04-13. NVD baseline CVSS 5.5; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
Trending — 3 sources updated this week
5.5
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS: 0%CVSS: 5.5Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

ipv6: avoid overflows in ip6_datagram_send_ctl()

Yiming Qian reported :

I believe I found a locally triggerable kernel bug in the IPv6 sendmsg ancillary-data path that can panic the kernel via skb_under_panic() (local DoS).

The core issue is a mismatch between:

  • a 16-bit length accumulator (struct ipv6_txoptions::opt_flen, type
__u16) and
  • a pointer to the *last* provided destination-options header (opt->dst1opt)

when multiple IPV6_DSTOPTS control messages (cmsgs) are provided.

  • include/net/ipv6.h:
  • struct ipv6_txoptions::opt_flen is __u16 (wrap possible).
(lines 291-307, especially 298)
  • net/ipv6/datagram.c:ip6_datagram_send_ctl():
  • Accepts repeated IPV6_DSTOPTS and accumulates into opt_flen
without rejecting duplicates. (lines 909-933)
  • net/ipv6/ip6_output.c:__ip6_append_data():
  • Uses opt->opt_flen + opt->opt_nflen to compute header
sizes/headroom decisions. (lines 1448-1466, especially 1463-1465)
  • net/ipv6/ip6_output.c:__ip6_make_skb():
  • Calls ipv6_push_frag_opts() if opt->opt_flen is non-zero.
(lines 1930-1934)
  • net/ipv6/exthdrs.c:ipv6_push_frag_opts() / ipv6_push_exthdr():
  • Push size comes from ipv6_optlen(opt->dst1opt) (based on the
pointed-to header). (lines 1179-1185 and 1206-1211)
  • opt_flen is a 16-bit accumulator:
  • include/net/ipv6.h:298 defines __u16 opt_flen; /* after fragment hdr */.
  • ip6_datagram_send_ctl() accepts *repeated* IPV6_DSTOPTS cmsgs
and increments opt_flen each time:
  • In net/ipv6/datagram.c:909-933, for IPV6_DSTOPTS:
  • It computes len = ((hdr->hdrlen + 1) << 3);
  • It checks CAP_NET_RAW using ns_capable(net->user_ns,
CAP_NET_RAW). (line 922)
  • Then it does:
  • opt->opt_flen += len; (line 927)
  • opt->dst1opt = hdr; (line 928)

There is no duplicate rejection here (unlike the legacy IPV6_2292DSTOPTS path which rejects duplicates at net/ipv6/datagram.c:901-904).

If enough large IPV6_DSTOPTS cmsgs are provided, opt_flen wraps while dst1opt still points to a large (2048-byte) destination-options header.

In the attached PoC (poc.c):

  • 32 cmsgs with hdrlen=255 => len = (255+1)*8 = 2048
  • 1 cmsg with hdrlen=0 => len = 8
  • Total increment: 32*2048 + 8 = 65544, so (__u16)opt_flen == 8
  • The last cmsg is 2048 bytes, so dst1opt points to a 2048-byte header.
  • The transmit path sizes headers using the wrapped opt_flen:
  • In net/ipv6/ip6_output.c:1463-1465:
  • headersize = sizeof(struct ipv6hdr) + (opt ? opt->opt_flen +
opt->opt_nflen : 0) + ...;

With wrapped opt_flen, headersize/headroom decisions underestimate what will be pushed later.

  • When building the final skb, the actual push length comes from
dst1opt and is not limited by wrapped opt_flen:
  • In net/ipv6/ip6_output.c:1930-1934:
  • if (opt->opt_flen) proto = ipv6_push_frag_opts(skb, opt, proto);
  • In net/ipv6/exthdrs.c:1206-1211, ipv6_push_frag_opts() pushes
dst1opt via ipv6_push_exthdr().
  • In net/ipv6/exthdrs.c:1179-1184, ipv6_push_exthdr() does:
  • skb_push(skb, ipv6_optlen(opt));
  • memcpy(h, opt, ipv6_optlen(opt));

With insufficient headroom, skb_push() underflows and triggers skb_under_panic() -> BUG():

  • net/core/skbuff.c:2669-2675 (skb_push() calls skb_under_panic())
  • net/core/skbuff.c:207-214 (skb_panic() ends in BUG())
  • The IPV6_DSTOPTS cmsg path requires CAP_NET_RAW in the target
netns user namespace (ns_capable(net->user_ns, CAP_NET_RAW)).
  • Root (or any task with CAP_NET_RAW) can trigger this without user
namespaces.
  • An unprivileged uid=1000 user can trigger this if unprivileged
user namespaces are enabled and it can create a userns+netns to obtain namespaced CAP_NET_RAW (the attached PoC does this).
  • Local denial of service: kernel BUG/panic (system crash).
  • ---truncated---

CVSS v3
5.5
EG Score
5.5(medium)
EG Risk
29(Track)
EG Risk 29/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity55% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS
1.7%
KEV
Not listed

Published

April 13, 2026

Last Modified

July 14, 2026

Advisory Details (10)

Auto-updated Jul 19, 2026
⚠️ Active exploitation confirmed. No patch confirmed yet.
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/9ed81d692758dfb9471d7799b24bfa7a08224c31
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/872b74900d5daa37067ac676d9001bb929fc6a2a
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/63fda74885555e6bd1623b5d811feec998740ba4
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/5e4ee5dbea134e9257f205e31a96040bed71e83f
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4e453375561fc60820e6b9d8ebeb6b3ee177d42e
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4082f9984a694829153115d28c956a3534f52f29
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/2dbfb003bbf3fc0e94f07efefab0ebcf83029a2a
generic

ipv6: avoid overflows in ip6_datagram_send_ctl() - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/0bdaf54d3aaddfe8df29371260fa8d4939b4fd6f

Vendor Advisories for CVE-2026-31415(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Patch Availability(1)

Vendor / EcosystemFixed in / PatchReleasedSource
linuxKernel @ 5.10.253osv

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 14× in last 7d / 36× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

Showing the most recent 100 of 106 total refreshes for this CVE.

  1. 2026-07-23 14:18 UTCEPSS rescore
  2. 2026-07-23 14:18 UTCEPSS rescore
  3. 2026-07-23 03:08 UTCEG score recompute
  4. 2026-07-22 14:08 UTCEPSS rescore
  5. 2026-07-22 14:08 UTCEPSS rescore
  6. 2026-07-21 15:24 UTCEPSS rescore
  7. 2026-07-21 15:24 UTCEPSS rescore
  8. 2026-07-20 17:08 UTCEPSS rescore
  9. 2026-07-20 17:08 UTCEPSS rescore
  10. 2026-07-20 12:02 UTCOSV refresh
  11. 2026-07-19 14:31 UTCEPSS rescore
  12. 2026-07-19 14:31 UTCEPSS rescore
  13. 2026-07-18 10:04 UTCEPSS rescore
  14. 2026-07-18 10:04 UTCEPSS rescore
  15. 2026-07-16 17:03 UTCEPSS rescore
  16. 2026-07-16 17:03 UTCEPSS rescore
  17. 2026-07-15 16:57 UTCEPSS rescore
  18. 2026-07-15 16:57 UTCEPSS rescore
  19. 2026-07-14 13:19 UTCNVD updateCVSS v3 → 5.5 · severity → MEDIUM
  20. 2026-07-14 13:11 UTCMITRE cvelistV5
  21. 2026-07-13 22:30 UTCEPSS rescore
  22. 2026-07-12 05:46 UTCEPSS rescore
  23. 2026-07-09 19:10 UTCEPSS rescore
  24. 2026-07-08 15:15 UTCEPSS rescore
  25. 2026-07-07 13:46 UTCEPSS rescore
Show 75 more
  1. 2026-07-06 02:23 UTCEPSS rescore
  2. 2026-07-06 02:23 UTCEPSS rescore
  3. 2026-07-05 02:30 UTCEPSS rescore
  4. 2026-07-04 06:31 UTCEPSS rescore
  5. 2026-07-01 15:06 UTCEPSS rescore
  6. 2026-06-30 23:22 UTCEPSS rescore
  7. 2026-06-28 14:07 UTCEPSS rescore
  8. 2026-06-28 14:07 UTCEPSS rescore
  9. 2026-06-28 04:56 UTCEPSS rescore
  10. 2026-06-28 04:56 UTCEPSS rescore
  11. 2026-06-27 03:08 UTCEPSS rescore
  12. 2026-06-23 21:33 UTCEPSS rescore
  13. 2026-06-23 21:33 UTCEPSS rescore
  14. 2026-06-21 14:56 UTCEPSS rescore
  15. 2026-06-21 14:56 UTCEPSS rescore
  16. 2026-06-21 01:59 UTCEPSS rescore
  17. 2026-06-19 19:25 UTCEPSS rescore
  18. 2026-06-19 19:25 UTCEPSS rescore
  19. 2026-06-18 17:52 UTCEPSS rescore
  20. 2026-06-18 17:52 UTCEPSS rescore
  21. 2026-06-17 17:53 UTCEPSS rescore
  22. 2026-06-16 17:52 UTCEPSS rescore
  23. 2026-06-15 17:49 UTCEPSS rescore
  24. 2026-06-14 23:18 UTCEPSS rescore
  25. 2026-06-14 21:54 UTCGHSA enrichment
  26. 2026-06-13 23:00 UTCEPSS rescore
  27. 2026-06-12 23:12 UTCEPSS rescore
  28. 2026-06-12 23:12 UTCEPSS rescore
  29. 2026-06-11 19:39 UTCGHSA enrichment
  30. 2026-06-11 14:00 UTCEPSS rescore
  31. 2026-06-10 22:18 UTCEPSS rescore
  32. 2026-06-10 13:22 UTCEPSS rescore
  33. 2026-06-10 09:28 UTCGHSA enrichment
  34. 2026-06-09 11:17 UTCGHSA enrichment
  35. 2026-06-08 14:17 UTCEPSS rescore
  36. 2026-06-08 14:17 UTCEPSS rescore
  37. 2026-06-08 05:35 UTCGHSA enrichment
  38. 2026-06-07 07:25 UTCGHSA enrichment
  39. 2026-06-06 13:47 UTCEPSS rescore
  40. 2026-06-06 13:47 UTCEPSS rescore
  41. 2026-06-05 22:47 UTCEPSS rescore
  42. 2026-06-05 22:47 UTCEPSS rescore
  43. 2026-06-05 06:10 UTCEPSS rescore
  44. 2026-06-05 06:10 UTCEPSS rescore
  45. 2026-06-04 13:12 UTCEPSS rescore
  46. 2026-06-04 13:12 UTCEPSS rescore
  47. 2026-06-02 21:00 UTCGHSA enrichment
  48. 2026-06-02 20:13 UTCEPSS rescore
  49. 2026-06-02 20:13 UTCEPSS rescore
  50. 2026-06-01 22:15 UTCGHSA enrichment
  51. 2026-06-01 13:51 UTCEPSS rescore
  52. 2026-06-01 13:51 UTCEPSS rescore
  53. 2026-05-31 22:30 UTCEPSS rescore
  54. 2026-05-31 22:30 UTCEPSS rescore
  55. 2026-05-31 00:16 UTCEPSS rescore
  56. 2026-05-31 00:16 UTCEPSS rescore
  57. 2026-05-29 13:44 UTCEPSS rescore
  58. 2026-05-29 13:44 UTCEPSS rescore
  59. 2026-05-28 13:44 UTCEPSS rescore
  60. 2026-05-28 13:44 UTCEPSS rescore
  61. 2026-05-28 13:44 UTCEPSS rescore
  62. 2026-05-27 13:40 UTCEPSS rescore
  63. 2026-05-27 13:40 UTCEPSS rescore
  64. 2026-05-27 13:40 UTCEPSS rescore
  65. 2026-05-26 13:44 UTCEPSS rescore
  66. 2026-05-26 13:44 UTCEPSS rescore
  67. 2026-05-26 07:18 UTCEPSS rescore
  68. 2026-05-26 07:18 UTCEPSS rescore
  69. 2026-05-26 07:18 UTCEPSS rescore
  70. 2026-05-24 16:59 UTCEPSS rescore
  71. 2026-05-23 15:21 UTCEPSS rescore
  72. 2026-05-22 21:16 UTCEPSS rescore
  73. 2026-05-20 22:38 UTCEPSS rescore
  74. 2026-05-20 22:38 UTCEPSS rescore
  75. 2026-05-20 22:37 UTCEPSS rescore

Frequently asked(5)

What is CVE-2026-31415?
CVE-2026-31415 is a medium vulnerability published on April 13, 2026. In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6datagramsend_ctl() Yiming Qian reported : <quote> I believe I found a locally triggerable kernel bug in the IPv6 sendmsg ancillary-data path that can panic the kernel via skbunderpanic() (local DoS). The…
When was CVE-2026-31415 disclosed?
CVE-2026-31415 was first published in the National Vulnerability Database on April 13, 2026, with the most recent update on July 14, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-31415 actively exploited?
CVE-2026-31415 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 1.7% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2026-31415?
CVE-2026-31415 has a CVSS v3 base score of 5.5 (NVD).
How do I remediate CVE-2026-31415?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-31415, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-31415

Explore →

Is Your Infrastructure Affected by CVE-2026-31415?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.