Junglewise Threat Intelligence

CVE-2026-31664: Linux Kernel heap memory leak in XFRM build_polexpire

CVE-2026-31664 · Severity: medium · CVSS 5.5 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to view sensitive information from the system's memory. The issue occurs when the kernel sends certain network policy expiration notifications to applications, accidentally including small amounts of uninitialized data from the kernel's internal memory. This could potentially leak cryptographic keys or other sensitive data to an unauthorized local observer.

Technical details

An information leak exists in the Linux kernel's XFRM (IPsec) implementation within net/xfrm/xfrm_user.c. The function build_polexpire() fails to initialize trailing padding bytes in the 'xfrm_user_polexpire' structure before sending it to userspace via netlink multicast (XFRMNLGRP_EXPIRE). A local attacker with the ability to listen to these netlink messages can capture uninitialized kernel heap memory. The fix involves using memset_after() or an equivalent manual memset to ensure all padding bytes are zeroed before transmission.

Affected products

  • Linux Linux Kernel versions from 2.6.12.1 up to 6.1.169; 6.2 up to 6.6.135; 6.7 up to 6.12.82; 6.13 up to 6.18.23; 6.19 up to 6.19.13

Timeline

  • 2026-03-26: other: Patch authored
  • 2026-04-24: disclosed: Initial publication of CVE-2026-31664
  • 2026-04-24: advisory
  • 2026-06-01: patched: Final stable tree updates applied

References

Related threats