CVE-2026-31786: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor a string. The first causes a buffer overflow as sprintf in buildid_show will read and copy till it finds a NUL. 00000000 f4 91 51 f4 dd 38 9e 9d 65 47 52 eb 10 71 db 50 |..Q..8..eGR..q.P| 00000010 b9 a8 01 42 6f 2e 32 |...Bo.2| 00000017 So use a memcpy instead of sprintf to have the correct value: 00000000 f4 91 51 f4 dd 00 9e 9d 65 47 52 eb 10 71 db 50 |..Q.....eGR..q.P| 00000010 b9 a8 01 42 |...B| 00000014 (the above have a hack to embed a zero inside and check it's returned correctly). This is XSA-485 / CVE-2026-31786

Affected products

  • Linux Linux Kernel: from 4.13, before 5.10.254 (fixed in 5.10.254); from 5.11, before 5.15.204 (fixed in 5.15.204); from 5.16, before 6.1.170 (fixed in 6.1.170); from 6.2, before 6.6.137 (fixed in 6.6.137); from 6.7, before 6.12.85 (fixed in 6.12.85); from 6.13, before 6.18.26 (fixed in 6.18.26); …

Published 2026-04-30. Last modified 2026-06-17.