CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()
iavf: fix out-of-bounds writes in iavfgetethtoolstats()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify iavf to use immutable num_tx_queues in all related functions (including iavf_get_ethtool_stats() / ETH_SS_STATS) to avoid out-of-bounds writes caused by runtime-changing real_num_tx_queues/num_active_queues when handling concurrent ethtool -L / ethtool -S channel/queue changes.
iavf (Intel iavf network driver) ethtool stats code paths Use immutable num_tx_queues instead of real_num_tx_queues/num_active_queues in related ethtool statistics functions = Immutable num_tx_queues for ETH_SS_STATS and all related functions (use num_tx_queues consistently)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31505?
The severity of CVE-2026-31505 is high, with a CVSS score of 7.8.
How do I fix CVE-2026-31505?
To fix CVE-2026-31505, you need to apply the available patch for the Linux kernel.
What is CVE-2026-31505 about?
CVE-2026-31505 addresses an out-of-bounds write vulnerability in the iavf driver of the Linux kernel.
Which software is affected by CVE-2026-31505?
CVE-2026-31505 affects the Linux kernel, specifically the iavf driver.
When was CVE-2026-31505 published?
CVE-2026-31505 was published on April 22, 2026.