{"id":"CVE-2026-31494","title":"net: macb: use the current queue number for stats","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: use the current queue number for stats\n\nThere's a potential mismatch between the memory reserved for statistics\nand the amount of memory written.\n\ngem_get_ss…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 9738be665544281aa624842812c2fbfed6f88226","Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 240c5302eed83e34e98db18f6795ee5f40814024","Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 9596759a84e1dbf2670518d85e969208960041f9","Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 95246341945163ad9a250a87ca5bd1c1252777ae","Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 9d74d10e4e26672e139a8bcf8bf95957bf2d160f","Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 7ff87da099210856cbfe2f2f7f52ddfa57af4f0c","Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < e182fe273cdf5a8931592228196ef514ffac392b","Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 72d96e4e24bbefdcfbc68bdb9341a05d8f5cb6e5","Linux 4.16"],"published":"2026-04-22","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:47:24.786Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31494","references":[{"url":"https://git.kernel.org/stable/c/9738be665544281aa624842812c2fbfed6f88226"},{"url":"https://git.kernel.org/stable/c/240c5302eed83e34e98db18f6795ee5f40814024"},{"url":"https://git.kernel.org/stable/c/9596759a84e1dbf2670518d85e969208960041f9"},{"url":"https://git.kernel.org/stable/c/95246341945163ad9a250a87ca5bd1c1252777ae"},{"url":"https://git.kernel.org/stable/c/9d74d10e4e26672e139a8bcf8bf95957bf2d160f"},{"url":"https://git.kernel.org/stable/c/7ff87da099210856cbfe2f2f7f52ddfa57af4f0c"},{"url":"https://git.kernel.org/stable/c/e182fe273cdf5a8931592228196ef514ffac392b"},{"url":"https://git.kernel.org/stable/c/72d96e4e24bbefdcfbc68bdb9341a05d8f5cb6e5"}],"tags":["cve.org"],"epss":0.00135,"epssPercentile":0.03342,"ingestedAt":"2026-09-08T15:33:26.990Z","slug":"CVE-2026-31494","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: use the current queue number for stats\n\nThere's a potential mismatch between the memory reserved for statistics\nand the amount of memory written.\n\ngem_get_sset_count() correctly computes the number of stats based on the\nactive queues, whereas gem_get_ethtool_stats() indiscriminately copies\ndata using the maximum number of queues, and in the case the number of\nactive queues is less than MACB_MAX_QUEUES, this results in a OOB write\nas observed in the KASAN splat.\n\n==================================================================\nBUG: KASAN: vmalloc-out-of-bounds in gem_get_ethtool_stats+0x54/0x78\n  [macb]\nWrite of size 760 at addr ffff80008080b000 by task ethtool/1027\n\nCPU: [...]\nTainted: [E]=UNSIGNED_MODULE\nHardware name: raspberrypi rpi/rpi, BIOS 2025.10 10/01/2025\nCall trace:\n show_stack+0x20/0x38 (C)\n dump_stack_lvl+0x80/0xf8\n print_report+0x384/0x5e0\n kasan_report+0xa0/0xf0\n kasan_check_range+0xe8/0x190\n __asan_memcpy+0x54/0x98\n gem_get_ethtool_stats+0x54/0x78 [macb\n   926c13f3af83b0c6fe64badb21ec87d5e93fcf65]\n dev_ethtool+0x1220/0x38c0\n dev_ioctl+0x4ac/0xca8\n sock_do_ioctl+0x170/0x1d8\n sock_ioctl+0x484/0x5d8\n __arm64_sys_ioctl+0x12c/0x1b8\n invoke_syscall+0xd4/0x258\n el0_svc_common.constprop.0+0xb4/0x240\n do_el0_svc+0x48/0x68\n el0_svc+0x40/0xf8\n el0t_64_sync_handler+0xa0/0xe8\n el0t_64_sync+0x1b0/0x1b8\n\nThe buggy address belongs to a 1-page vmalloc region starting at\n  0xffff80008080b000 allocated at dev_ethtool+0x11f0/0x38c0\nThe buggy address belongs to the physical page:\npage: refcount:1 mapcount:0 mapping:0000000000000000\n  index:0xffff00000a333000 pfn:0xa333\nflags: 0x7fffc000000000(node=0|zone=0|lastcpupid=0x1ffff)\nraw: 007fffc000000000 0000000000000000 dead000000000122 0000000000000000\nraw: ffff00000a333000 0000000000000000 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\n\nMemory state around the buggy address:\n ffff80008080b080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ffff80008080b100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n>ffff80008080b180: 00 00 00 00 00 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n                                  ^\n ffff80008080b200: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ffff80008080b280: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n==================================================================\n\nFix it by making sure the copied size only considers the active number of\nqueues.\n\n## Affected\n\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 9738be665544281aa624842812c2fbfed6f88226`\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 240c5302eed83e34e98db18f6795ee5f40814024`\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 9596759a84e1dbf2670518d85e969208960041f9`\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 95246341945163ad9a250a87ca5bd1c1252777ae`\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 9d74d10e4e26672e139a8bcf8bf95957bf2d160f`\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 7ff87da099210856cbfe2f2f7f52ddfa57af4f0c`\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < e182fe273cdf5a8931592228196ef514ffac392b`\n- `Linux >= 512286bbd4b7d5b15d26ba8078c8bfd1fc1129bd < 72d96e4e24bbefdcfbc68bdb9341a05d8f5cb6e5`\n- `Linux 4.16`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}