CVE-2026-31402
A critical flaw in the Linux kernel’s NFSv4.0 replay cache can let an attacker overwrite memory on the server. The bug happens when a lock request is denied and the kernel copies too much data into a small buffer, potentially allowing arbitrary code execution. The issue has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Linux kernel versions that include the NFSv4.0 implementation, such as 2.6.12 and 7.0, are affected. The vulnerability applies to any system running an NFSv4.0 server.
Real-world impact
An attacker could trigger the flaw by coordinating two NFSv4.0 clients, causing the server to write beyond the bounds of a heap buffer. This could corrupt memory, leading to denial of service or arbitrary code execution on the NFS server.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication, requires no user interaction, and can compromise confidentiality, integrity, and availability of the affected system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the CVE-2026-31402 fix.
- 02Reboot the system so the new kernel is loaded.
NVD description indicates the vulnerability has been resolved.
Timeline
- Apr 3, 2026 · Apr 3, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/0f0e2a54a31a7f9ad2…patch
- git.kernel.org/stable/c/2665887a69437a8a4f…
- git.kernel.org/stable/c/5133b61aaf437e5f25…patch
- git.kernel.org/stable/c/8afb437ea1f70cacb4…patch
- git.kernel.org/stable/c/ae8498337dfdfda71b…patch
- git.kernel.org/stable/c/c9452c0797c95cf237…patch
- git.kernel.org/stable/c/dad0c3c0a8e5d1d6eb…patch
- git.kernel.org/stable/c/f9fcb4441f6c02bb20…patch
- access.redhat.com/errata/RHSA-2026:10108
- access.redhat.com/errata/RHSA-2026:11313
- access.redhat.com/errata/RHSA-2026:13565
- access.redhat.com/errata/RHSA-2026:13566
- access.redhat.com/errata/RHSA-2026:13577
- access.redhat.com/errata/RHSA-2026:13578
- access.redhat.com/errata/RHSA-2026:13664
- access.redhat.com/errata/RHSA-2026:13681
- access.redhat.com/errata/RHSA-2026:13734
- access.redhat.com/errata/RHSA-2026:13936
- access.redhat.com/errata/RHSA-2026:14137
- access.redhat.com/errata/RHSA-2026:14165