[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-DEBIAN-CVE-2026-31505":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-30T21:17:53.703Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":16,"duplicates":17,"related":18,"reserved_at":9,"published_at":19,"modified_at":20,"state":9,"summary":21,"references_raw":23,"kevs":30,"epss":9,"epss_history":31,"metrics":32,"affected":39},"DEBIAN-CVE-2026-31505","In the Linux kernel, the following vulnerability has been resolved:  iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()  iavf incorrectly uses real_num_tx_queues for ETH_SS_STATS. Since the value could change in runtime, we should use num_tx_queues instead.  Moreover iavf_get_ethtool_stats() uses num_active_queues while iavf_get_sset_count() and iavf_get_stat_strings() use real_num_tx_queues, which triggers out-of-bounds writes when we do \"ethtool -L\" and \"ethtool -S\" simultaneously [1].  For example when we change channels from 1 to 8, Thread 3 could be scheduled before Thread 2, and out-of-bounds writes could be triggered in Thread 3:  Thread 1 (ethtool -L)       Thread 2 (work)        Thread 3 (ethtool -S) iavf_set_channels() ... iavf_alloc_queues() -> num_active_queues = 8 iavf_schedule_finish_config()                                                    iavf_get_sset_count()                                                    real_num_tx_queues: 1                                                    -> buffer for 1 queue                                                    iavf_get_ethtool_stats()                                                    num_active_queues: 8                                                    -> out-of-bounds!                             iavf_finish_config()                             -> real_num_tx_queues = 8  Use immutable num_tx_queues in all related functions to avoid the issue.  [1]  BUG: KASAN: vmalloc-out-of-bounds in iavf_add_one_ethtool_stat+0x200/0x270  Write of size 8 at addr ffffc900031c9080 by task ethtool/5800   CPU: 1 UID: 0 PID: 5800 Comm: ethtool Not tainted 6.19.0-enjuk-08403-g8137e3db7f1c #241 PREEMPT(full)  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014  Call Trace:   \u003CTASK>   dump_stack_lvl+0x6f/0xb0   print_report+0x170/0x4f3   kasan_report+0xe1/0x180   iavf_add_one_ethtool_stat+0x200/0x270   iavf_get_ethtool_stats+0x14c/0x2e0   __dev_ethtool+0x3d0c/0x5830   dev_ethtool+0x12d/0x270   dev_ioctl+0x53c/0xe30   sock_do_ioctl+0x1a9/0x270   sock_ioctl+0x3d4/0x5e0   __x64_sys_ioctl+0x137/0x1c0   do_syscall_64+0xf3/0x690   entry_SYSCALL_64_after_hwframe+0x77/0x7f  RIP: 0033:0x7f7da0e6e36d  ...   \u003C/TASK>   The buggy address belongs to a 1-page vmalloc region starting at 0xffffc900031c9000 allocated at __dev_ethtool+0x3cc9/0x5830  The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000  index:0xffff88813a013de0 pfn:0x13a013  flags: 0x200000000000000(node=0|zone=2)  raw: 0200000000000000 0000000000000000 dead000000000122 0000000000000000  raw: ffff88813a013de0 0000000000000000 00000001ffffffff 0000000000000000  page dumped because: kasan: bad access detected   Memory state around the buggy address:   ffffc900031c8f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8   ffffc900031c9000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  >ffffc900031c9080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8                     ^   ffffc900031c9100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8   ffffc900031c9180: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8",null,[],[],[],[14],{"_key":15},"CVE-2026-31505",[],[],[],"2026-04-22T14:16:49.233Z","2026-06-15T19:06:15.928543701Z",{"cisa_kev":22,"cisa_ransomware":22,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[24],{"url":25,"sources":26,"tags":28},"https://security-tracker.debian.org/tracker/CVE-2026-31505",[27],"osv_debian",[29],"Advisory",[],[],[33],{"source":27,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":34,"cvss_v4_0":9},{"baseScore":35,"baseSeverity":9,"vectorString":36,"impactScore":37,"exploitabilityScore":38},7.8,"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",9.8,4.6,[40],{"ecosystem":41,"name":42,"vendor":43,"product":42,"cpe_part":9,"purl_type":44,"purl_namespace":43,"purl_name":42,"source":9,"versions":45},"Debian","linux","debian","deb",[46,50,51,55],{"version":47,"is_range":48,"range_type":49,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all",true,"ecosystem",{"version":47,"is_range":48,"range_type":49,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":52,"is_range":48,"range_type":49,"version_start":9,"version_start_type":9,"version_end":53,"version_end_type":54,"fixed_in":9},"lt6_12_85_1","6.12.85-1","excluding",{"version":56,"is_range":48,"range_type":49,"version_start":9,"version_start_type":9,"version_end":57,"version_end_type":54,"fixed_in":9},"lt6_19_11_1","6.19.11-1"]