Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-31469

7.8 · HIGH
Published Apr 22, 2026 linux CWE-416 EPSS 0.14% (3th pctl)

Overview

CVE-2026-31469 is a high-severity vulnerability affecting linux linux_kernel. It was published on April 22, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false

A UAF issue occurs when the virtio_net driver is configured with napi_tx=N

and the device's IFF_XMIT_DST_RELEASE flag is cleared

(e.g., during the configuration of tc route filter rules).

When IFF_XMIT_DST_RELEASE is removed from the net_device, the network stack

expects the driver to hold the reference to skb->dst until the packet

is fully transmitted and freed. In virtio_net with napi_tx=N,

skbs may remain in the virtio transmit ring for an extended period.

If the network namespace is destroyed while these skbs are still pending,

the corresponding dst_ops structure has freed. When a subsequent packet

is transmitted, free_old_xmit() is triggered to clean up old skbs.

It then calls dst_release() on the skb associated with the stale dst_entry.

Since the dst_ops (referenced by the dst_entry) has already been freed,

a UAF kernel p

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 2.6.26, < 5.10.253 Affected

Frequently Asked Questions

What is CVE-2026-31469?

CVE-2026-31469 is a high-severity vulnerability affecting linux linux_kernel. It was published on April 22, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2026-31469?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-31469?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-31469?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-31469 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.