CVE-2026-31630: rxrpc: proc: size address buffers for %pISpc output
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: proc: size address buffers for %pISpc output
The AFRXRPC procfs helpers format local and remote socket addresses into fixed 50-byte stack buffers with "%pISpc".
That is too small for the longest current-tree IPv6-with-port form the formatter can produce. In lib/vsprintf.c, the compressed IPv6 path uses a dotted-quad tail not only for v4mapped addresses, but also for ISATAP addresses via ipv6addrisisatap().
As a result, a case such as
[ffff:ffff:ffff:ffff:0:5efe:255.255.255.255]:65535
is possible with the current formatter. That is 50 visible characters, so 51 bytes including the trailing NUL, which does not fit in the existing char[50] buffers used by net/rxrpc/proc.c.
Size the buffers from the formatter's maximum textual form and switch the call sites to scnprintf().
Changes since v1: - correct the changelog to cite the actual maximum current-tree case explicitly - frame the proof around the ISATAP formatting path instead of the earlier mapped-v4 example
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31630?
CVE-2026-31630 has been classified as a medium-severity vulnerability affecting the Linux kernel.
How do I fix CVE-2026-31630?
To fix CVE-2026-31630, users should upgrade to the latest version of the Linux kernel that addresses this vulnerability.
Which versions of the Linux kernel are affected by CVE-2026-31630?
CVE-2026-31630 affects Linux kernel versions from 4.9.1 up to 6.18.23 and from 6.19 to 6.19.13, along with specific release candidates of version 7.0.
What type of vulnerability is CVE-2026-31630?
CVE-2026-31630 is a vulnerability related to buffer size handling for socket address formatting in the Linux kernel.
Is CVE-2026-31630 remotely exploitable?
CVE-2026-31630 is not specified as remotely exploitable; it primarily affects local socket handling.