HOMEVULNERABILITIESCVE-2026-31774
HIGH

CVE-2026-31774

Published: May 1, 2026· Updated: May 7, 2026

7.1
CVSS v3.1
EPSS:0.01%probability of exploitation in 30 daysPercentile:1.7th

Official Description

In the Linux kernel, the following vulnerability has been resolved:

io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs()

sqe->len is __u32 but gets stored into sr->len which is int. When

userspace passes sqe->len values exceeding INT_MAX (e.g. 0xFFFFFFFF),

sr->len overflows to a negative value. This negative value propagates

through the bundle recv/send path:

1. io_recv(): sel.val = sr->len (ssize_t gets -1)

2. io_recv_buf_select(): arg.max_len = sel->val (size_t gets

0xFFFFFFFFFFFFFFFF)

3. io_ring_buffers_peek(): buf->len is not clamped because max_len

is astronomically large

4. iov[].iov_len = 0xFFFFFFFF flows into io_bundle_nbufs()

5. io_bundle_nbufs(): min_t(int, 0xFFFFFFFF, ret) yields -1,

causing ret to increase instead of decrease, creating an

infinite loop that reads past the allocated iov[] array

This results in a slab-out-of-bounds read in io_bundle_nbufs() from

the kmalloc-64 slab, as nbufs increments past the allocated iovec

entries.

BUG: KASAN: slab-out-of-bounds in io_bundle_nbufs+0x128/0x160

Read of size 8 at addr ffff888100ae05c8 by task exp/145

Call Trace:

io_bundle_nbufs+0x128/0x160

io_recv_finish+0x117/0xe20

io_recv+0x2db/0x1160

Fix this by rejecting negative sr->len values early in both

io_sendmsg_prep() and io_recvmsg_prep(). Since sqe->len is __u32,

any value > INT_MAX indicates overflow and is not a valid length.

NVD Source

Technical Analysis

CVE-2026-31774 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

A successful exploit results in complete confidentiality breach (data exposure), availability disruption (denial of service), with a CVSS base score of 7.1.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityLow
Privileges Req.Low
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityNone
AvailabilityHigh
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Affected Vendors & Products

Linux1 product
linux kernel
Source: NVD CPE · 2 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (4)

Quick Facts

CVE IDCVE-2026-31774
CVSS Score7.1 / 10
SeverityHIGH
CISA KEVNo
EPSS (30d)0.01%
Affected1 vendor
PublishedMay 1, 2026

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-31774 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWATCH.COM. CVE data is provided under the NVD usage policy.