CVE-2026-31429 is a mismatched memory deallocation vulnerability in Linux kernel socket buffer head handling when KFENCE is enabled. The skb_kfree_head() function distinguishes dedicated small-head cache allocations from generic kmalloc allocations using skb_end_offset. For KFENCE allocations, kfence_ksize() returns the requested allocation size rather than the slab bucket size. If kzalloc() allocates a socket buffer head with a size equal to SKB_SMALL_HEAD_CACHE_SIZE, slab_build_skb() can produce an skb_end_offset matching SKB_SMALL_HEAD_HEADROOM. The free path consequently misidentifies the allocation and frees it to skb_small_head_cache instead of its original kmalloc cache.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, self-contained local Linux kernel proof-of-concept for CVE-2026-31429, a slab cross-cache free bug in the networking stack involving KFENCE and the skb free path. The repo contains three files: a detailed README explaining root cause, affected/fixed versions, and impact; a single C PoC source file; and a dmesg log showing successful reproduction. The exploit code is not part of a framework. The main code file, cve-2026-31429-poc-only.c, builds a minimal eBPF program and interacts directly with the bpf syscall using raw syscall numbers and manually populated attribute buffers. It uses BPF_PROG_LOAD (cmd 5) to load a trivial 3-instruction program, then repeatedly invokes BPF_PROG_TEST_RUN (cmd 10) with a hardcoded 284-byte syzkaller-derived input buffer. The PoC also creates fixed-address mmap regions to mimic syzkaller-style execution environment. Its purpose is to drive execution into bpf_prog_test_run_skb(), causing an skb allocation/free sequence that, when KFENCE exact-size semantics are present, results in skb_kfree_head() freeing an object into skb_small_head_cache even though it originated from kmalloc-1k. Capabilities are limited to vulnerability triggering and kernel warning generation. The code does not include a weaponized payload, shell, persistence, networking, or remote delivery. The expected outcome is a kernel WARN / slab corruption indicator visible in dmesg, not code execution. The included dmesg.txt corroborates this by showing warn_free_bad_obj, the mismatched cache message, and a call trace through skb_free_head, skb_release_data, bpf_prog_test_run_skb, and __sys_bpf. Attack surface is local only: a user on the target system must be able to invoke the bpf syscall and meet kernel/environment prerequisites. Based on the README, the vulnerable range begins at Linux 6.3 and is fixed in 6.12.82, 6.18.23, 6.19.13, and 7.0 mainline. Overall, this is a credible PoC/reproducer for a kernel memory-management flaw, not a full exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel networking memory-management flaw causes a slab cross-cache free when KFENCE allocation sizes lead to incorrect identification of an skb head's allocation cache. The reference rates it Medium, with CVSS v3 5.5, local attack access, low privileges required, and high availability impact. The fix uses kfree(head) to avoid allocator-specific misclassification.
A Linux kernel networking memory-management vulnerability causes a slab cross-cache free when KFENCE allocation-size reporting leads to incorrect skb head classification. The advisory rates it Medium, with a CVSS v3 score of 5.5, indicating local exploitation requiring low privileges and potentially high availability impact. The fix uses kfree(head) to avoid allocator-specific misclassification.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.