{"id":"CVE-2026-31670","title":"net: rfkill: prevent unlimited numbers of rfkill events from being created","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rfkill: prevent unlimited numbers of rfkill events from being created\n\nUserspace can create an unlimited number of rfkill events if the system\nis so configured, wh…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 4bcd1615a4e2a185ae9edd27b4143d7dfa7134f4","Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < b1e0c8d3ab58a0161db487bf5fc47adfcaf5d5ca","Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < e3842779547c83150569071d9980517cc9029fc0","Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 673d2a3eef6e0ee9736501a150c9e4024a4e60a6","Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 82843afc19012a29ba863961ef494165aa1a88f4","Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < a8c26800e0220e1550af012f5a20e50f5c78864d","Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 80ce4cb026f0a4c4532b6cad827b44debda6256a","Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < ea245d78dec594372e27d8c79616baf49e98a4a1","Linux 2.6.31"],"published":"2026-04-24","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:48:00.614Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31670","references":[{"url":"https://git.kernel.org/stable/c/4bcd1615a4e2a185ae9edd27b4143d7dfa7134f4"},{"url":"https://git.kernel.org/stable/c/b1e0c8d3ab58a0161db487bf5fc47adfcaf5d5ca"},{"url":"https://git.kernel.org/stable/c/e3842779547c83150569071d9980517cc9029fc0"},{"url":"https://git.kernel.org/stable/c/673d2a3eef6e0ee9736501a150c9e4024a4e60a6"},{"url":"https://git.kernel.org/stable/c/82843afc19012a29ba863961ef494165aa1a88f4"},{"url":"https://git.kernel.org/stable/c/a8c26800e0220e1550af012f5a20e50f5c78864d"},{"url":"https://git.kernel.org/stable/c/80ce4cb026f0a4c4532b6cad827b44debda6256a"},{"url":"https://git.kernel.org/stable/c/ea245d78dec594372e27d8c79616baf49e98a4a1"}],"tags":["cve.org"],"epss":0.0012,"epssPercentile":0.02077,"ingestedAt":"2026-09-08T15:33:26.989Z","slug":"CVE-2026-31670","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: rfkill: prevent unlimited numbers of rfkill events from being created\n\nUserspace can create an unlimited number of rfkill events if the system\nis so configured, while not consuming them from the rfkill file\ndescriptor, causing a potential out of memory situation.  Prevent this\nfrom bounding the number of pending rfkill events at a \"large\" number\n(i.e. 1000) to prevent abuses like this.\n\n## Affected\n\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 4bcd1615a4e2a185ae9edd27b4143d7dfa7134f4`\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < b1e0c8d3ab58a0161db487bf5fc47adfcaf5d5ca`\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < e3842779547c83150569071d9980517cc9029fc0`\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 673d2a3eef6e0ee9736501a150c9e4024a4e60a6`\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 82843afc19012a29ba863961ef494165aa1a88f4`\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < a8c26800e0220e1550af012f5a20e50f5c78864d`\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < 80ce4cb026f0a4c4532b6cad827b44debda6256a`\n- `Linux >= c64fb01627e24725d1f9d535e4426475a4415753 < ea245d78dec594372e27d8c79616baf49e98a4a1`\n- `Linux 2.6.31`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}