In the Linux kernel, the following vulnerability has been resolved:
media: dvb-net: fix OOB access in ULE extension header tables
The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables
in handle_one_ule_extension() are declared with 255 elements (valid
indices 0-254), but the index htype is derived from network-controlled
data as (ule_sndu_type & 0x00FF), giving a range of 0-255. When
htype equals 255, an out-of-bounds read occurs on the function pointer
table, and the OOB value may be called as a function pointer.
Add a bounds check on htype against the array size before either table
is accessed. Out-of-range values now cause the SNDU to be discarded.
References
Configurations
Configuration 1 (hide)
|
History
20 May 2026, 12:01
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* |
|
| References | () https://git.kernel.org/stable/c/145e50c2c700fa52b840df7bab206043997dd18e - Patch | |
| References | () https://git.kernel.org/stable/c/1a6da3dbb9985d00743073a1cc1f96e59f5abc30 - Patch | |
| References | () https://git.kernel.org/stable/c/24d87712727a5017ad142d63940589a36cd25647 - Patch | |
| References | () https://git.kernel.org/stable/c/29ef43ceb121d67b87f4cbb08439e4e9e732eff8 - Patch | |
| References | () https://git.kernel.org/stable/c/8bde543d2a5f935ba2a6a6325a2e02f8a9256fbe - Patch | |
| References | () https://git.kernel.org/stable/c/b2bd2ee73b697c177157bba534e1b1064c2e66a0 - Patch | |
| References | () https://git.kernel.org/stable/c/e51238718217c4abdb3ccc3b0c0cde265c7ec629 - Patch | |
| References | () https://git.kernel.org/stable/c/f2b65dcb78c8990e4c68a906627433be1fe38a92 - Patch | |
| CWE | CWE-125 | |
| First Time |
Linux linux Kernel
Linux |
27 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
18 Apr 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
06 Apr 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 08:16
Updated : 2026-05-20 12:01
NVD link : CVE-2026-31405
Mitre link : CVE-2026-31405
CVE.ORG link : CVE-2026-31405
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-125
Out-of-bounds Read
