CVE-2026-31684 is a Linux kernel flaw in the traffic control checksum action code in net/sched/act_csum.c, specifically in tcf_csum_act(). When processing packets that contain in-payload nested VLAN tags, the function walks nested VLAN headers directly from skb->data and reads h_vlan_encapsulated_proto, then advances by VLAN_HLEN, without first ensuring that the full VLAN header is present in the skb linear area. If only part of an inner VLAN header has been linearized, the code can read past the linear area and the subsequent skb_pull(VLAN_HLEN) can violate skb invariants. The upstream fix adds pskb_may_pull(skb, VLAN_HLEN) validation before accessing and pulling each nested VLAN header, and drops the packet through the existing error path if the header is still not fully available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel vulnerability in net/sched/act_csum involving validation of nested VLAN headers, fixed by this Red Hat kernel update.
A Linux kernel networking vulnerability in net sched act_csum related to validation of nested VLAN headers.
A kernel vulnerability in net/sched/act_csum involving validation of nested VLAN headers.
A Linux kernel networking vulnerability in net/sched/act_csum related to validation of nested VLAN headers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.