[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-31415":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":20,"duplicate_of":9,"upstream":21,"downstream":22,"duplicates":31,"related":32,"reserved_at":9,"published_at":33,"modified_at":34,"state":35,"summary":36,"references_raw":45,"kevs":80,"epss":81,"epss_history":84,"metrics":242,"affected":248},"CVE-2026-31415","In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: avoid overflows in ip6_datagram_send_ctl()\n\nYiming Qian reported :\n\u003Cquote>\n I believe I found a locally triggerable kernel bug in the IPv6 sendmsg\n ancillary-data path that can panic the kernel via `skb_under_panic()`\n (local DoS).\n\n The core issue is a mismatch between:\n\n - a 16-bit length accumulator (`struct ipv6_txoptions::opt_flen`, type\n `__u16`) and\n - a pointer to the *last* provided destination-options header (`opt->dst1opt`)\n\n when multiple `IPV6_DSTOPTS` control messages (cmsgs) are provided.\n\n - `include/net/ipv6.h`:\n   - `struct ipv6_txoptions::opt_flen` is `__u16` (wrap possible).\n (lines 291-307, especially 298)\n - `net/ipv6/datagram.c:ip6_datagram_send_ctl()`:\n   - Accepts repeated `IPV6_DSTOPTS` and accumulates into `opt_flen`\n without rejecting duplicates. (lines 909-933)\n - `net/ipv6/ip6_output.c:__ip6_append_data()`:\n   - Uses `opt->opt_flen + opt->opt_nflen` to compute header\n sizes/headroom decisions. (lines 1448-1466, especially 1463-1465)\n - `net/ipv6/ip6_output.c:__ip6_make_skb()`:\n   - Calls `ipv6_push_frag_opts()` if `opt->opt_flen` is non-zero.\n (lines 1930-1934)\n - `net/ipv6/exthdrs.c:ipv6_push_frag_opts()` / `ipv6_push_exthdr()`:\n   - Push size comes from `ipv6_optlen(opt->dst1opt)` (based on the\n pointed-to header). (lines 1179-1185 and 1206-1211)\n\n 1. `opt_flen` is a 16-bit accumulator:\n\n - `include/net/ipv6.h:298` defines `__u16 opt_flen; /* after fragment hdr */`.\n\n 2. `ip6_datagram_send_ctl()` accepts *repeated* `IPV6_DSTOPTS` cmsgs\n and increments `opt_flen` each time:\n\n - In `net/ipv6/datagram.c:909-933`, for `IPV6_DSTOPTS`:\n   - It computes `len = ((hdr->hdrlen + 1) \u003C\u003C 3);`\n   - It checks `CAP_NET_RAW` using `ns_capable(net->user_ns,\n CAP_NET_RAW)`. (line 922)\n   - Then it does:\n     - `opt->opt_flen += len;` (line 927)\n     - `opt->dst1opt = hdr;` (line 928)\n\n There is no duplicate rejection here (unlike the legacy\n `IPV6_2292DSTOPTS` path which rejects duplicates at\n `net/ipv6/datagram.c:901-904`).\n\n If enough large `IPV6_DSTOPTS` cmsgs are provided, `opt_flen` wraps\n while `dst1opt` still points to a large (2048-byte)\n destination-options header.\n\n In the attached PoC (`poc.c`):\n\n - 32 cmsgs with `hdrlen=255` => `len = (255+1)*8 = 2048`\n - 1 cmsg with `hdrlen=0` => `len = 8`\n - Total increment: `32*2048 + 8 = 65544`, so `(__u16)opt_flen == 8`\n - The last cmsg is 2048 bytes, so `dst1opt` points to a 2048-byte header.\n\n 3. The transmit path sizes headers using the wrapped `opt_flen`:\n\n- In `net/ipv6/ip6_output.c:1463-1465`:\n  - `headersize = sizeof(struct ipv6hdr) + (opt ? opt->opt_flen +\n opt->opt_nflen : 0) + ...;`\n\n With wrapped `opt_flen`, `headersize`/headroom decisions underestimate\n what will be pushed later.\n\n 4. When building the final skb, the actual push length comes from\n `dst1opt` and is not limited by wrapped `opt_flen`:\n\n - In `net/ipv6/ip6_output.c:1930-1934`:\n   - `if (opt->opt_flen) proto = ipv6_push_frag_opts(skb, opt, proto);`\n - In `net/ipv6/exthdrs.c:1206-1211`, `ipv6_push_frag_opts()` pushes\n `dst1opt` via `ipv6_push_exthdr()`.\n - In `net/ipv6/exthdrs.c:1179-1184`, `ipv6_push_exthdr()` does:\n   - `skb_push(skb, ipv6_optlen(opt));`\n   - `memcpy(h, opt, ipv6_optlen(opt));`\n\n With insufficient headroom, `skb_push()` underflows and triggers\n `skb_under_panic()` -> `BUG()`:\n\n - `net/core/skbuff.c:2669-2675` (`skb_push()` calls `skb_under_panic()`)\n - `net/core/skbuff.c:207-214` (`skb_panic()` ends in `BUG()`)\n\n - The `IPV6_DSTOPTS` cmsg path requires `CAP_NET_RAW` in the target\n netns user namespace (`ns_capable(net->user_ns, CAP_NET_RAW)`).\n - Root (or any task with `CAP_NET_RAW`) can trigger this without user\n namespaces.\n - An unprivileged `uid=1000` user can trigger this if unprivileged\n user namespaces are enabled and it can create a userns+netns to obtain\n namespaced `CAP_NET_RAW` (the attached PoC does this).\n\n - Local denial of service: kernel BUG/panic (system crash).\n -\n---truncated---",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-617","Reachable Assertion","The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.","weakness","Draft","Base",[],[],[],[],[23,25,27,29],{"_key":24},"MGASA-2026-0108",{"_key":26},"MGASA-2026-0110",{"_key":28},"DEBIAN-CVE-2026-31415",{"_key":30},"UBUNTU-CVE-2026-31415",[],[],"2026-04-13T13:21:03.284Z","2026-05-11T22:08:16.113Z","Analyzed",{"cisa_kev":37,"cisa_ransomware":37,"cisa_vendor":9,"epss_severity":38,"epss_score":39,"severity":40,"severity_score":41,"severity_version":42,"severity_source":43,"severity_vector":44,"severity_status":35},false,"low",0.00015,"medium",5.5,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",[46,52,56,60,64,68,72,76],{"url":47,"sources":48,"tags":50},"https://git.kernel.org/stable/c/0bdaf54d3aaddfe8df29371260fa8d4939b4fd6f",[49,43],"cve.org",[51],"Patch",{"url":53,"sources":54,"tags":55},"https://git.kernel.org/stable/c/5e4ee5dbea134e9257f205e31a96040bed71e83f",[49,43],[51],{"url":57,"sources":58,"tags":59},"https://git.kernel.org/stable/c/63fda74885555e6bd1623b5d811feec998740ba4",[49,43],[51],{"url":61,"sources":62,"tags":63},"https://git.kernel.org/stable/c/9ed81d692758dfb9471d7799b24bfa7a08224c31",[49,43],[51],{"url":65,"sources":66,"tags":67},"https://git.kernel.org/stable/c/872b74900d5daa37067ac676d9001bb929fc6a2a",[49,43],[51],{"url":69,"sources":70,"tags":71},"https://git.kernel.org/stable/c/4e453375561fc60820e6b9d8ebeb6b3ee177d42e",[49,43],[51],{"url":73,"sources":74,"tags":75},"https://git.kernel.org/stable/c/2dbfb003bbf3fc0e94f07efefab0ebcf83029a2a",[49,43],[51],{"url":77,"sources":78,"tags":79},"https://git.kernel.org/stable/c/4082f9984a694829153115d28c956a3534f52f29",[49,43],[51],[],{"date":82,"score":39,"percentile":83},"2026-06-04",0.03329,[85,89,92,95,98,101,105,108,111,114,117,120,123,126,129,132,135,138,141,144,147,150,153,156,159,162,165,168,171,174,177,180,184,187,190,193,196,199,202,205,208,211,214,217,220,223,226,229,232,235,238,241],{"date":86,"score":87,"percentile":88},"2026-04-14",0.0003,0.08473,{"date":90,"score":87,"percentile":91},"2026-04-15",0.08488,{"date":93,"score":87,"percentile":94},"2026-04-16",0.08491,{"date":96,"score":87,"percentile":97},"2026-04-17",0.0848,{"date":99,"score":87,"percentile":100},"2026-04-18",0.08477,{"date":102,"score":103,"percentile":104},"2026-04-19",0.00039,0.11847,{"date":106,"score":103,"percentile":107},"2026-04-20",0.11826,{"date":109,"score":103,"percentile":110},"2026-04-21",0.11993,{"date":112,"score":103,"percentile":113},"2026-04-22",0.12053,{"date":115,"score":103,"percentile":116},"2026-04-23",0.12062,{"date":118,"score":103,"percentile":119},"2026-04-24",0.11971,{"date":121,"score":103,"percentile":122},"2026-04-25",0.11968,{"date":124,"score":103,"percentile":125},"2026-04-26",0.11941,{"date":127,"score":103,"percentile":128},"2026-04-27",0.11916,{"date":130,"score":103,"percentile":131},"2026-04-28",0.11864,{"date":133,"score":103,"percentile":134},"2026-04-29",0.11841,{"date":136,"score":103,"percentile":137},"2026-04-30",0.11821,{"date":139,"score":103,"percentile":140},"2026-05-01",0.11793,{"date":142,"score":103,"percentile":143},"2026-05-02",0.11827,{"date":145,"score":103,"percentile":146},"2026-05-03",0.1181,{"date":148,"score":103,"percentile":149},"2026-05-04",0.1176,{"date":151,"score":103,"percentile":152},"2026-05-05",0.11759,{"date":154,"score":103,"percentile":155},"2026-05-06",0.11751,{"date":157,"score":103,"percentile":158},"2026-05-07",0.11894,{"date":160,"score":103,"percentile":161},"2026-05-08",0.11903,{"date":163,"score":103,"percentile":164},"2026-05-09",0.11943,{"date":166,"score":103,"percentile":167},"2026-05-10",0.11927,{"date":169,"score":103,"percentile":170},"2026-05-11",0.11917,{"date":172,"score":103,"percentile":173},"2026-05-12",0.11946,{"date":175,"score":103,"percentile":176},"2026-05-13",0.11966,{"date":178,"score":103,"percentile":179},"2026-05-14",0.12005,{"date":181,"score":182,"percentile":183},"2026-05-15",0.00043,0.13279,{"date":185,"score":182,"percentile":186},"2026-05-16",0.13293,{"date":188,"score":182,"percentile":189},"2026-05-17",0.13277,{"date":191,"score":182,"percentile":192},"2026-05-18",0.13225,{"date":194,"score":182,"percentile":195},"2026-05-19",0.13205,{"date":197,"score":182,"percentile":198},"2026-05-20",0.13204,{"date":200,"score":39,"percentile":201},"2026-05-21",0.03302,{"date":203,"score":39,"percentile":204},"2026-05-22",0.03475,{"date":206,"score":39,"percentile":207},"2026-05-23",0.03463,{"date":209,"score":39,"percentile":210},"2026-05-24",0.03443,{"date":212,"score":39,"percentile":213},"2026-05-25",0.03424,{"date":215,"score":39,"percentile":216},"2026-05-26",0.03399,{"date":218,"score":39,"percentile":219},"2026-05-27",0.03421,{"date":221,"score":39,"percentile":222},"2026-05-28",0.03397,{"date":224,"score":39,"percentile":225},"2026-05-29",0.03401,{"date":227,"score":39,"percentile":228},"2026-05-30",0.03431,{"date":230,"score":39,"percentile":231},"2026-05-31",0.03419,{"date":233,"score":39,"percentile":234},"2026-06-01",0.03369,{"date":236,"score":39,"percentile":237},"2026-06-02",0.0334,{"date":239,"score":39,"percentile":240},"2026-06-03",0.03331,{"date":82,"score":39,"percentile":83},[243],{"source":43,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":244,"cvss_v4_0":9},{"baseScore":41,"baseSeverity":245,"vectorString":44,"impactScore":246,"exploitabilityScore":247},"MEDIUM",6,4.6,[249,284],{"ecosystem":9,"name":250,"vendor":251,"product":251,"cpe_part":252,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":253},"Linux","linux","a",[254,261,264,267,270,273,276,279,282],{"version":255,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":259,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 2dbfb003bbf3fc0e94f07efefab0ebcf83029a2a",true,"333fad5364d6b457c8d837f7d05802d2aaf8a961","including","2dbfb003bbf3fc0e94f07efefab0ebcf83029a2a","excluding",{"version":262,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":263,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 4082f9984a694829153115d28c956a3534f52f29","4082f9984a694829153115d28c956a3534f52f29",{"version":265,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":266,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 0bdaf54d3aaddfe8df29371260fa8d4939b4fd6f","0bdaf54d3aaddfe8df29371260fa8d4939b4fd6f",{"version":268,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":269,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 5e4ee5dbea134e9257f205e31a96040bed71e83f","5e4ee5dbea134e9257f205e31a96040bed71e83f",{"version":271,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":272,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 63fda74885555e6bd1623b5d811feec998740ba4","63fda74885555e6bd1623b5d811feec998740ba4",{"version":274,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":275,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 9ed81d692758dfb9471d7799b24bfa7a08224c31","9ed81d692758dfb9471d7799b24bfa7a08224c31",{"version":277,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":278,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 872b74900d5daa37067ac676d9001bb929fc6a2a","872b74900d5daa37067ac676d9001bb929fc6a2a",{"version":280,"is_range":256,"range_type":49,"version_start":257,"version_start_type":258,"version_end":281,"version_end_type":260,"fixed_in":9},">= 333fad5364d6b457c8d837f7d05802d2aaf8a961, \u003C 4e453375561fc60820e6b9d8ebeb6b3ee177d42e","4e453375561fc60820e6b9d8ebeb6b3ee177d42e",{"version":283,"is_range":37,"range_type":49,"version_start":283,"version_start_type":258,"version_end":283,"version_end_type":258,"fixed_in":9},"2.6.14",{"ecosystem":9,"name":285,"vendor":251,"product":286,"cpe_part":287,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":288},"linux kernel","linux_kernel","o",[289,293,297,301,305,309,313,317,319,321,323,325,327,329],{"version":290,"is_range":256,"range_type":291,"version_start":283,"version_start_type":258,"version_end":292,"version_end_type":260,"fixed_in":9},"gte2.6.14_lt5.10.253","cpe","5.10.253",{"version":294,"is_range":256,"range_type":291,"version_start":295,"version_start_type":258,"version_end":296,"version_end_type":260,"fixed_in":9},"gte5.11_lt5.15.203","5.11","5.15.203",{"version":298,"is_range":256,"range_type":291,"version_start":299,"version_start_type":258,"version_end":300,"version_end_type":260,"fixed_in":9},"gte5.16_lt6.1.168","5.16","6.1.168",{"version":302,"is_range":256,"range_type":291,"version_start":303,"version_start_type":258,"version_end":304,"version_end_type":260,"fixed_in":9},"gte6.2_lt6.6.134","6.2","6.6.134",{"version":306,"is_range":256,"range_type":291,"version_start":307,"version_start_type":258,"version_end":308,"version_end_type":260,"fixed_in":9},"gte6.7_lt6.12.81","6.7","6.12.81",{"version":310,"is_range":256,"range_type":291,"version_start":311,"version_start_type":258,"version_end":312,"version_end_type":260,"fixed_in":9},"gte6.13_lt6.18.22","6.13","6.18.22",{"version":314,"is_range":256,"range_type":291,"version_start":315,"version_start_type":258,"version_end":316,"version_end_type":260,"fixed_in":9},"gte6.19_lt6.19.12","6.19","6.19.12",{"version":318,"is_range":37,"range_type":291,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc1",{"version":320,"is_range":37,"range_type":291,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc2",{"version":322,"is_range":37,"range_type":291,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc3",{"version":324,"is_range":37,"range_type":291,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc4",{"version":326,"is_range":37,"range_type":291,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc5",{"version":328,"is_range":37,"range_type":291,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc6",{"version":330,"is_range":37,"range_type":291,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc7"]