CVE-2026-31525: bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
Published Apr 22, 2026
·Updated
bpf: Fix undefined behavior in interpreter sdiv/smod for INTMIN
Affected Software
10 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=6.6<6.6.131
Linux Linux kernel>=6.7<6.12.80
Linux Linux kernel>=6.13<6.18.21
Linux Linux kernel>=6.19<6.19.11
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Microsoft azl3 kernel 6.6.130.1-3
Event History
Apr 22, 2026
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionSeverity
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 23, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:09 AM
Affected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-31525?
CVE-2026-31525 is classified as a moderate severity vulnerability in the Linux kernel.
2
What impact does CVE-2026-31525 have on system security?
CVE-2026-31525 can lead to undefined behavior in the BPF interpreter, potentially affecting system stability and security.
3
How do I fix CVE-2026-31525?
To fix CVE-2026-31525, users should update to the latest stable version of the Linux kernel that includes the patch.
4
Which software is affected by CVE-2026-31525?
CVE-2026-31525 affects the Linux kernel, specifically the BPF interpreter's handling of signed 32-bit division and modulo operations.
5
Is there a workaround for CVE-2026-31525?
There are no known effective workarounds for CVE-2026-31525; updating the kernel is recommended.