LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31682

CVE-2026-31682 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: April 27, 2026

Linux Kernel - Out of Bounds Read/Write

Published: April 25, 2026Updated: April 27, 2026Remote Exploitable

Overview

Linux kernel contains a buffer linearization issue in br_nd_send function caused by parsing non-linear neighbour discovery options, letting attackers cause memory corruption or denial of service, exploit requires crafted network packets.

Severity & Score

Severity: Critical
CVSS Score: 9.1
EPSS Score: 6.9%(Probability of exploitation in next 30 days)

Impact

Attackers can cause memory corruption or denial of service by sending crafted network packets.

Mitigation

Update to the latest Linux kernel version containing the fix.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 27, 2026

šŸ”“ CVE-2026-31682 - Critical (9.1) In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and assumes that these options are in the linear part ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-31682/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-31682
Severity
Critical
CVSS Score
9.1
Type
out_of_bounds_rw
Status
unconfirmed
EPSS
6.9%
Social Posts
1

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS Score

6.9%Probability of exploitation in the next 30 days