PT-2026-34898 · Linux · Linux Kernel

CVE-2026-31546

·

Published

2026-04-24

·

Updated

2026-07-23

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference exists in the bonding network subsystem. The function bond debug rlb hash show() accesses client info->slave without verifying if the value is NULL. This occurs because rlb clear slave() may leave RLB hash-table entries on the rx hashtbl used head list with the slave set to NULL when no replacement slave is available, potentially leading to a kernel crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31546
ECHO-0B28-A403-9102
OESA-2026-2581
OPENSUSE-SU-2026:20965-1
SUSE-SU-2026:22099-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22112-1
SUSE-SU-2026:22117-1
SUSE-SU-2026:22127-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:2450-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8575-1
USN-8575-2
USN-8576-1
USN-8576-2
USN-8595-1
USN-8596-1
USN-8597-1

Affected Products

Linux Kernel