A Linux kernel flaw tracked as CVE-2026-31684 was disclosed in the network scheduler's act_csum code, where improperly validated nested VLAN headers can trigger an out-of-bounds read. The bug affects tcf_csum_act() in net/sched/act_csum.c, which may access h_vlan_encapsulated_proto and pull VLAN_HLEN bytes from skb->data before confirming the full VLAN header is present in the linear buffer, breaking skb invariants and potentially crashing the system.
The issue was introduced in kernel 5.1, with an additional affected introduction point noted in 4.19.99, and has been fixed upstream in 6.12.83, 6.18.24, 6.19.14, and 7.0. Red Hat rated the vulnerability Moderate with a CVSS v3 score of 7.1 and published fixes for multiple Red Hat Enterprise Linux kernel packages across RHEL 7, 8, and 10 through security errata; the Linux kernel CVE team advised users to update to the latest stable kernel releases rather than cherry-picking individual commits.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-28, Red Hat issued RHSA-2026:21557 for RHEL 10, RHSA-2026:21745 for RHEL 8 kernel-rt, and RHSA-2026:21706 for RHEL 8 kernel to address CVE-2026-31684.
Red Hat published its CVE-2026-31684 entry on 2026-04-25, classifying the Linux kernel flaw as Moderate severity and describing a denial-of-service risk from specially crafted packets with nested VLAN headers.
On 2026-04-25, the Linux kernel CVE team published an announcement for CVE-2026-31684, describing an out-of-bounds read issue in net/sched/act_csum.c related to nested VLAN headers. The advisory recommended updating to the latest stable kernel release rather than cherry-picking individual commits.
On 2026-07-30, Red Hat issued RHSA-2026:47633 for the RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages to address CVE-2026-31684.
On 2026-07-23, Red Hat issued RHSA-2026:44694 for Red Hat Enterprise Linux 10.0 Extended Update Support to fix CVE-2026-31684.
On 2026-07-17, Red Hat issued RHSA-2026:41234 for RHEL 7 Extended Lifecycle Support kernel-rt and RHSA-2026:41235 for RHEL 7 Extended Lifecycle Support kernel to address CVE-2026-31684.
On 2026-07-15, Red Hat issued RHSA-2026:40068 for the RHEL 8.6 support streams to fix CVE-2026-31684.
The Linux kernel fixed CVE-2026-31684 in versions 6.12.83, 6.18.24, 6.19.14, and 7.0 by adding validation to ensure each nested VLAN header is fully present before access and pull operations. The fix drops packets through the existing error path when the header is still not fully available.
The nested VLAN header validation flaw later tracked as CVE-2026-31684 was introduced in Linux kernel 5.1. The Linux kernel CVE advisory also notes an additional introduction point in 4.19.99.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.