CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-31405

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-125

Description

In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255 elements (valid indices 0-254), but the index htype is derived from network-controlled data as (ule_sndu_type & 0x00FF), giving a range of 0-255. When htype equals 255, an out-of-bounds read occurs on the function pointer table, and the OOB value may be called as a function pointer. Add a bounds check on htype against the array size before either table is accessed. Out-of-range values now cause the SNDU to be discarded.

Affected packages

Linux Kernel 2.6.12 → 5.10.253
Linux Kernel 5.11.0 → 5.15.203
Linux Kernel 5.16.0 → 6.1.167
Linux Kernel 6.13.0 → 6.18.19
Linux Kernel 6.19.0 → 6.19.9
Linux Kernel 6.2.0 → 6.6.130
Linux Kernel 6.7.0 → 6.12.78

References

Status: profiled · ingested 2026-07-25T00:00:18.000Z