Affects Linux kernel core infrastructure; high severity RCE with wide deployment across enterprises.
CVE-2026-31685
Kernel netfilter eui64 MAC header bug enables RCE.
Is CVE-2026-31685 being exploited?
Not confirmed. CVE-2026-31685 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.34% probability of exploitation in the next 30 days.
How severe is CVE-2026-31685?
CVE-2026-31685 is rated Critical with a CVSS score of 9.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-31685?
Yes. A fix has been recorded for CVE-2026-31685. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-31685 affect?
CVE-2026-31685 affects Linux kernel (netfilter ip6t_eui64). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-31685?
Patch kernel immediately; reboot if required
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote code execution via crafted IPv6 packets with invalid MAC header; attacker can run code in kernel context.
Immediate action required
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 4d75bc2cd093bf5803edf512c099bfb220fd6459
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 7d6a57411caf54df025860c9b1a82cd42d57a562
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < d5603591373441fecf9951833d6d873e09320f08
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 288138418bef956f8b295751a4536c60f0e89f4a
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 9eda5478746ef7dc0e4e537b5a5e4b0ca1027091
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 807d6ee15804df6f01a35c910f09612e858739a6
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 309ae3e9a51a69699ca94eac5fac5688fa562d55
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < fdce0b3590f724540795b874b4c8850c90e6b0a8
- affected2.6.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.