๐Ÿ” CVE Alert

CVE-2026-31664

UNKNOWN 0.0

xfrm: clear trailing padding in build_polexpire()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() build_expire() clears the trailing padding bytes of struct xfrm_user_expire after setting the hard field via memset_after(), but the analogous function build_polexpire() does not do this for struct xfrm_user_polexpire. The padding bytes after the __u8 hard field are left uninitialized from the heap allocation, and are then sent to userspace via netlink multicast to XFRMNLGRP_EXPIRE listeners, leaking kernel heap memory contents. Add the missing memset_after() call, matching build_expire().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Apr 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ac6985903db047eaff54db929e4bf6b06782788e 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c221ed63a2769a0af8bd849dfe25740048f34ef4 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < eda30846ea54f8ed218468e5480c8305ca645e37 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b1dfd6b27df35ef4f87825aa5f607378d23ff0f2 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e1af65c669ebb1666c54576614c01a7f9ffcfff6 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 71a98248c63c535eaa4d4c22f099b68d902006d0
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ac6985903db047eaff54db929e4bf6b06782788e git.kernel.org: https://git.kernel.org/stable/c/c221ed63a2769a0af8bd849dfe25740048f34ef4 git.kernel.org: https://git.kernel.org/stable/c/eda30846ea54f8ed218468e5480c8305ca645e37 git.kernel.org: https://git.kernel.org/stable/c/b1dfd6b27df35ef4f87825aa5f607378d23ff0f2 git.kernel.org: https://git.kernel.org/stable/c/e1af65c669ebb1666c54576614c01a7f9ffcfff6 git.kernel.org: https://git.kernel.org/stable/c/71a98248c63c535eaa4d4c22f099b68d902006d0