PT-2026-36383 · Linux · Linux Kernel

CVE-2026-31748

·

Published

2026-02-05

·

Updated

2026-07-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A buffer overrun can occur in the me2600 xilinx download() function when loading firmware requested by request firmware(). The function reads a data stream length into the file length variable from the first 4 bytes of the file and subsequently reads the data stream starting from offset 16. While the system verifies that the firmware is at least 16 bytes long, it fails to confirm if the total file size is sufficient to contain the data stream specified by file length, leading to a potential source buffer overrun.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10736
CVE-2026-31748
ECHO-7D00-5447-35D3
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4

Affected Products

Linux Kernel