CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock
Published Apr 25, 2026
·Updated
afunix: read UNIXDIAGVFS data under unixstatelock
Affected Software
13 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.134.1-2
Linux Linux kernel>=3.3<6.6.136
Linux Linux kernel>=6.7<6.12.83
Linux Linux kernel>=6.13<6.18.24
Linux Linux kernel>=6.19<6.19.14
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Event History
Apr 25, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverity
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityAffected Software
Apr 26, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-31673?
CVE-2026-31673 has a severity rating classified as high due to potential unauthorized information disclosure.
2
How do I fix CVE-2026-31673?
To fix CVE-2026-31673, you should update your Linux kernel to the latest stable version where the vulnerability has been patched.
3
What systems are affected by CVE-2026-31673?
CVE-2026-31673 affects the Linux kernel, specifically versions prior to the security patch.
4
What are the potential impacts of CVE-2026-31673?
The potential impacts of CVE-2026-31673 include an unauthorized read of UNIX_DIAG_VFS data that could lead to information leaks.
5
Is CVE-2026-31673 being actively exploited?
As of now, there is no indication that CVE-2026-31673 is being actively exploited in the wild.