CVE-2026-31405 | Linux Kernel up to 7.0-rc2 handle_one_ule_extension out-of-bounds (EUVD-2026-19199)
A vulnerability was found in Linux Kernel up to 7.0-rc2. It has been declared as critical. The impacted element is the function handle_one_ule_extension. The manipulation of the argument ule_mandatory_ext_handlers[]/ule_optional_ext_handlers[] results in out-of-bounds read.
This vulnerability is cataloged as CVE-2026-31405. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.