PT-2026-34377 · Linux · Linux Kernel

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-31472

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the xfrm IPTFS component where the inner IPv4 header length in IPTFS payloads is not properly validated within the input process payload() function. A specially crafted ESP packet containing an inner IPv4 header with a tot len of 0 can trigger an infinite loop. This occurs because the data offset fails to advance, causing the system to spin indefinitely in the softirq context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2026-31472

Affected Products

Linux Kernel