PT-2026-35020 · Linux · Linux Kernel

Published

2026-04-24

·

Updated

2026-05-29

·

CVE-2026-31668

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the seg6 lwtunnel, a single dst cache per encap route is shared between the seg6 input core() and seg6 output core() functions. Because these two paths can perform post-encap SID lookups in different routing contexts, such as VRF table separation or ip rules matching on the ingress interface, the path that executes first populates the cache. The subsequent path then reuses this cached data without performing its own lookup, effectively bypassing the intended routing context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-31668
ECHO-1266-1F5A-2356
OESA-2026-2492

Affected Products

Linux Kernel