CVE-2026-31411

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc pointer from msg->vcc and uses it directly without any validation. This pointer comes from userspace via sendmsg() and can be arbitrarily forged: int fd = socket(AF_ATMSVC, SOCK_DGRAM, 0); ioctl(fd, ATMSIGD_CTRL); // become ATM signaling daemon struct msghdr msg = { .msg_iov = &iov, ... }; *(unsigned long *)(buf + 4) = 0xdeadbeef; // fake vcc pointer sendmsg(fd, &msg, 0); // kernel dereferences 0xdeadbeef In normal operation, the kernel sends the vcc pointer to the signaling daemon via sigd_enq() when processing operations like connect(), bind(), or listen(). The daemon is expected to return the same pointer when responding. However, a malicious daemon can send arbitrary pointer values. Fix this by introducing find_get_vcc() which validates the pointer by searching through vcc_hash (similar to how sigd_close() iterates over all VCCs), and acquires a reference via sock_hold() if found. Since struct atm_vcc embeds struct sock as its first member, they share the same lifetime. Therefore using sock_hold/sock_put is sufficient to keep the vcc alive while it is being used. Note that there may be a race with sigd_close() which could mark the vcc with various flags (e.g., ATM_VF_RELEASED) after find_get_vcc() returns. However, sock_hold() guarantees the memory remains valid, so this race only affects the logical state, not memory safety. [1]: https://gist.github.com/mrpre/1ba5949c45529c511152e2f4c755b0f3
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

History

25 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: atm: corrige un fallo debido a un puntero vcc no validado en sigd_send() Reproductor disponible en [1]. La ruta de envío de ATM (sendmsg -> vcc_sendmsg -> sigd_send) lee el puntero vcc de msg -> vcc y lo usa directamente sin ninguna validación. Este puntero proviene del espacio de usuario a través de sendmsg() y puede ser forjado arbitrariamente: int fd = socket(AF_ATMSVC, SOCK_DGRAM, 0); ioctl(fd, ATMSIGD_CTRL); // se convierte en demonio de señalización ATM struct msghdr msg = { .msg_iov = &iov, ... }; *(unsigned long *)(buf + 4) = 0xdeadbeef; // puntero vcc falso sendmsg(fd, &msg, 0); // el kernel desreferencia 0xdeadbeef En operación normal, el kernel envía el puntero vcc al demonio de señalización a través de sigd_enq() al procesar operaciones como connect(), bind() o listen(). Se espera que el demonio devuelva el mismo puntero al responder. Sin embargo, un demonio malicioso puede enviar valores de puntero arbitrarios. Esto se soluciona introduciendo find_get_vcc() que valida el puntero buscando en vcc_hash (similar a cómo sigd_close() itera sobre todos los VCC), y adquiere una referencia a través de sock_hold() si se encuentra. Dado que struct atm_vcc incrusta struct sock como su primer miembro, comparten la misma vida útil. Por lo tanto, usar sock_hold/sock_put es suficiente para mantener el vcc activo mientras se está utilizando. Tenga en cuenta que puede haber una condición de carrera con sigd_close() que podría marcar el vcc con varias banderas (por ejemplo, ATM_VF_RELEASED) después de que find_get_vcc() retorne. Sin embargo, sock_hold() garantiza que la memoria permanece válida, por lo que esta condición de carrera solo afecta el estado lógico, no la seguridad de la memoria. [1]: https://gist.github.com/mrpre/1ba5949c45529c511152e2f4c755b0f3

14 Jul 2026, 13:18

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-019113.html -
  • () https://cert-portal.siemens.com/productcert/html/ssa-082556.html -

20 May 2026, 16:03

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/1c8bda3df028d5e54134077dcd09f46ca8cfceb5 - () https://git.kernel.org/stable/c/1c8bda3df028d5e54134077dcd09f46ca8cfceb5 - Patch
References () https://git.kernel.org/stable/c/21c303fec138c002f90ed33bce60e807d53072bb - () https://git.kernel.org/stable/c/21c303fec138c002f90ed33bce60e807d53072bb - Patch
References () https://git.kernel.org/stable/c/3e1a8b00095246a9a2b46b57f6d471c6d3c00ed2 - () https://git.kernel.org/stable/c/3e1a8b00095246a9a2b46b57f6d471c6d3c00ed2 - Patch
References () https://git.kernel.org/stable/c/440c9a5fc477a8ee259d8bf669531250b8398651 - () https://git.kernel.org/stable/c/440c9a5fc477a8ee259d8bf669531250b8398651 - Patch
References () https://git.kernel.org/stable/c/69d3f9ee5489e6e8b66defcfa226e91d82393297 - () https://git.kernel.org/stable/c/69d3f9ee5489e6e8b66defcfa226e91d82393297 - Patch
References () https://git.kernel.org/stable/c/ae88a5d2f29b69819dc7b04086734439d074a643 - () https://git.kernel.org/stable/c/ae88a5d2f29b69819dc7b04086734439d074a643 - Patch
References () https://git.kernel.org/stable/c/c96549d07dfdd51aadf0722cfb40711574424840 - () https://git.kernel.org/stable/c/c96549d07dfdd51aadf0722cfb40711574424840 - Patch
References () https://git.kernel.org/stable/c/e3f80666c2739296c3b69a127300455c43aa1067 - () https://git.kernel.org/stable/c/e3f80666c2739296c3b69a127300455c43aa1067 - Patch

08 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 14:16

Updated : 2026-07-25 10:10


NVD link : CVE-2026-31411

Mitre link : CVE-2026-31411

CVE.ORG link : CVE-2026-31411


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference