Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-31435— netfs: Fix read abandonment during retry

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netfs在重试期间读取放弃问题,可能导致子请求变量未正确设置,引发意外行为。

CVSS 8.8 · High EPSS 0.34% · P27

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux ee4cdf7ba857a894ad1650d6ab77669cbbfa329e< 3e5fd8f53b575ff2188f82071da19c977ca56c41 affected
ee4cdf7ba857a894ad1650d6ab77669cbbfa329e< 8f2f2bd128a8d9edbc1e785760da54ada3df69b7 affected
ee4cdf7ba857a894ad1650d6ab77669cbbfa329e< 7e57523490cd2efb52b1ea97f2e0a74c0fb634cd affected
6.12 affected
< 6.12 unaffected
6.18.21≤ 6.18.* unaffected
6.19.11≤ 6.19.* unaffected
7.0≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-31435

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfs: Fix read abandonment during retry
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under certain circumstances, all the remaining subrequests from a read request will get abandoned during retry. The abandonment process expects the 'subreq' variable to be set to the place to start abandonment from, but it doesn't always have a useful value (it will be uninitialised on the first pass through the loop and it may point to a deleted subrequest on later passes). Fix the first jump to "abandon:" to set subreq to the start of the first subrequest expected to need retry (which, in this abandonment case, turned out unexpectedly to no longer have NEED_RETRY set). Also clear the subreq pointer after discarding superfluous retryable subrequests to cause an oops if we do try to access it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netfs在重试期间读取放弃问题,可能导致子请求变量未正确设置,引发意外行为。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ee4cdf7ba857a894ad1650d6ab77669cbbfa329e ~ 3e5fd8f53b575ff2188f82071da19c977ca56c41 -
Linux Linux 6.12 -

II. Public POCs for CVE-2026-31435

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-31435

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-04-22 · 100 CVEs total

CVE-2026-31463 9.8 CRITICAL iomap: fix invalid folio access when i_blkbits differs from I/O granularity
CVE-2026-31436 9.8 CRITICAL dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc()
CVE-2026-31444 9.8 CRITICAL ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
CVE-2026-31478 9.8 CRITICAL ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len()
CVE-2026-31501 9.8 CRITICAL net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path
CVE-2026-31448 9.4 CRITICAL ext4: avoid infinite loops caused by residual data
CVE-2026-31432 8.8 HIGH ksmbd: fix OOB write in QUERY_INFO for compound requests
CVE-2026-31433 8.8 HIGH ksmbd: fix potencial OOB in get_file_all_info() for compound requests
CVE-2026-31450 8.8 HIGH ext4: publish jinode after initialization
CVE-2026-31476 8.2 HIGH ksmbd: do not expire session on binding failure
CVE-2026-31464 8.1 HIGH scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()
CVE-2026-31513 8.1 HIGH Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req
CVE-2026-31488 7.8 HIGH drm/amd/display: Do not skip unrelated mode changes in DSC validation
CVE-2026-31479 7.8 HIGH drm/xe: always keep track of remap prev/next
CVE-2026-31490 7.8 HIGH drm/xe/pf: Fix use-after-free in migration restore
CVE-2026-31494 7.8 HIGH net: macb: use the current queue number for stats
CVE-2026-31502 7.8 HIGH team: fix header_ops type confusion with non-Ethernet ports
CVE-2026-31449 7.8 HIGH ext4: validate p_idx bounds in ext4_ext_correct_indexes
CVE-2026-31504 7.8 HIGH net: fix fanout UAF in packet_release() via NETDEV_UP race
CVE-2026-31505 7.8 HIGH iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()

Showing top 20 of 100 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-31435

No comments yet


Leave a comment