A flaw in the Linux kernel's netfilter ip6t_eui64 component, tracked as CVE-2026-31685, allowed specially crafted IPv6 packets to trigger access to an invalid MAC header and potentially crash vulnerable systems. The bug was in eui64_mt6(), where the code could still call eth_hdr(skb) when the packet's MAC header was invalid if the fragment offset was zero, creating a remote denial-of-service condition during IPv6 packet processing.
The issue affected code dating back to Linux kernel 2.6.12 and was fixed by rejecting invalid MAC headers for all packets before Ethernet header access. Upstream fixes were released across several stable kernel branches, including 6.12.83, 6.18.24, 6.19.14, and 7.0, while Red Hat shipped patches through security errata for multiple RHEL 7, 8, 9, and 10 product variants. Red Hat rated the flaw Moderate with a CVSS 7.1 for its products, although cve.org listed a 9.4 score, and both upstream and vendor guidance advised updating to the latest supported kernel packages.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat released security errata fixing CVE-2026-31685 for RHEL 10 (RHSA-2026:21557), RHEL 9 (RHSA-2026:21556), and RHEL 8 including kernel and kernel-rt packages (RHSA-2026:21706 and RHSA-2026:21745).
The Linux kernel CVE team published CVE-2026-31685, explaining that ip6t_eui64 must reject invalid MAC headers for all packets and documenting fixes across multiple stable branches.
Red Hat's record for CVE-2026-31685 was made public, describing a Linux kernel netfilter flaw that could let crafted IPv6 packets trigger a denial-of-service condition.
Red Hat issued RHSA-2026:41236 to fix CVE-2026-31685 in Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel-rt packages.
Red Hat released RHSA-2026:26535 to address CVE-2026-31685 in Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On.
Red Hat shipped RHSA-2026:25533 to fix CVE-2026-31685 for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On.
Red Hat released RHSA-2026:25095 to remediate CVE-2026-31685 in Red Hat Enterprise Linux 7 Extended Lifecycle Support.
Red Hat issued RHSA-2026:24343 to address CVE-2026-31685 in Red Hat Enterprise Linux 10.0 Extended Update Support.
The flaw was fixed upstream in Linux kernel releases 6.12.83, 6.18.24, 6.19.14, and 7.0 by removing the condition that only rejected invalid MAC headers when par->fragoff was nonzero.
The vulnerable behavior in netfilter's ip6t_eui64 component was introduced in Linux kernel 2.6.12, allowing eui64_mt6() to reach eth_hdr(skb) for some packets with invalid MAC headers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.