PT-2026-32152 · Linux · Linux Kernel

Published

2026-04-12

·

Updated

2026-05-20

·

CVE-2026-31413

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the BPF verifier related to unsound scalar forking in the maybe fork scalars() function when handling BPF OR operations. Specifically, the function incorrectly forks the verifier state, leading to a divergence between the verifier and runtime values. This divergence can result in out-of-bounds map access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-05267
CVE-2026-31413

Affected Products

Linux Kernel