PT-2026-34399 · Linux · Linux Kernel

Published

2026-04-22

·

Updated

2026-05-26

·

CVE-2026-31494

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A mismatch exists between the memory reserved for statistics and the amount of memory written in the macb network driver. The function gem get sset count() calculates the number of statistics based on active queues, but gem get ethtool stats() copies data using the maximum number of queues. When the number of active queues is less than MACB MAX QUEUES, this results in an out-of-bounds write.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31494
ECHO-2ADF-02E5-5A89

Affected Products

Linux Kernel