CVE-2026-31494

medium Red Hat
Published: April 22, 2026 (22 days ago)
Last Modified: April 22, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's macb network driver. A local user can exploit this vulnerability due to an out-of-bounds write in the gem_get_ethtool_stats function. This occurs when the driver incorrectly copies data using the maximum number of queues instead of the active number, leading to memory corruption. This can result in a kernel crash, causing a Denial of Service (DoS) for the system.

CWE

CWE-787

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References