VDB

CVE-2026-31679

CVE-2026-31679 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: openvswitch: validate MPLS set/set_masked payload length validate_set() accepted OVS_KEY_ATTR_MPLS as variable-sized payload for SET/SET_MASKED actions. In action handling, OVS expects fixed-size MPLS key data (struct ovs_key_mpls). Use the already normalized key_len (masked case included) and reject non-matching MPLS action key sizes. Reject invalid MPLS action payload lengths early.

EPSS 0.02% · 3.6th percentile

Risk Scores

EPSS Score
0.02%
3.6th percentile

Affected Products

VendorProductVersions
linuxlinux_kernel5.5, 5.5, 5.5
LinuxLinuxfbdcdd78da7c95f1b970d371e1b23cbd3aa990f3, fbdcdd78da7c95f1b970d371e1b23cbd3aa990f3, fbdcdd78da7c95f1b970d371e1b23cbd3aa990f3

Timeline

  • Apr 25, 2026 CVE Published
  • Apr 25, 2026 PoC Published
  • Apr 27, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score

References

…and 57 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›