CVE-2026-31405

medium Red Hat
EPSS Score
0.0%
Exploitation probability in 30 days
Top 99% most likely to be exploited
Published: April 6, 2026 (38 days ago)
Last Modified: April 6, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's dvb-net component. A remote attacker could exploit this vulnerability by sending specially crafted network data. This could lead to an out-of-bounds read in the `handle_one_ule_extension()` function, potentially allowing the attacker to execute arbitrary code. The issue arises because an index derived from network-controlled data can exceed the bounds of an internal function pointer table.

CWE

CWE-1285

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References