Skip to main content
QUIETLYTIC
Vulnerability

Linux Kernel Vulnerability (CVE-2026-46331)

CVE-2026-46331 is a CVSS 7.8 integer-overflow flaw in the Linux kernel packet-editing traffic control action, per VulnCheck.

CVE-2026-46331
Threat Level
HIGH
CVSS
7.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Linux Kernel

CVE-2026-46331 carries a CVSS 3.1 base score of 7.8 against the Linux kernel. NVD classifies it under both CWE-190 (Integer Overflow or Wraparound) and CWE-787 (Out-of-Bounds Write). VulnCheck’s KEV feed reports the CVE as exploited, dated August 26, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-46331 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description, sourced from the upstream kernel fix commit, locates the bug in the kernel’s net/sched packet-editing (pedit) traffic control action, which lets an administrator configure rules that rewrite packet header fields as they pass through the kernel’s traffic-shaping subsystem. NVD states the function that computes how much of a packet buffer needs to be made writable calculates that amount once, using a value that doesn’t account for header offsets certain key types add at runtime — meaning part of the region a later write touches may not have been properly prepared as writable memory first, corrupting the underlying page rather than the packet copy. NVD’s fix adds overflow checking to the offset arithmetic and moves the writable-region calculation to run per-edit-key rather than once upfront.

We are reporting the nature of this calculation gap and its consequence — kernel memory corruption reachable through a misconfigured or attacker-influenced traffic-control rule — rather than the specific configuration needed to trigger it, which is available in the upstream kernel commit NVD cites for readers who need it for patch verification.

Evidence and confidence

  • Medium confidence — the CVSS 7.8 score, the vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and the CWE-190/CWE-787 classification, which trace to NVD alone in our current ingestion, corroborated by the upstream kernel fix commits NVD links. The exploitation report traces to VulnCheck KEV alone.
  • Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00583, a 46.3rd percentile score as of our ingestion.

No field is in conflict between our two sources. Our data carries no single fixed-version field; the upstream kernel commits NVD links identify the corrected code across multiple stable kernel branches, and Red Hat has issued a substantial number of distribution errata referencing this CVE.

Why this matters

Like the CVSS vector on this cycle’s other Linux kernel entry, this flaw is local (AV:L) rather than remotely reachable, requiring low privileges to trigger — the profile of a privilege-escalation or container/sandbox-escape primitive rather than a directly internet-facing threat. The net/sched packet-editing action is typically configured by an administrator for legitimate traffic-shaping purposes, but the number of Red Hat distribution errata referencing this CVE (dozens, spanning multiple product versions) signals how widely this code path is shipped across enterprise Linux deployments, and how broad the patching surface is for organizations running affected kernels.

Frequently Asked Questions

What is CVE-2026-46331? A CVSS 7.8 integer-overflow and out-of-bounds-write vulnerability (CWE-190/CWE-787) in the Linux kernel’s net/sched packet-editing traffic control action, caused by a writable-buffer-size calculation that doesn’t account for runtime header offsets.

Is CVE-2026-46331 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 26, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need remote network access to exploit this? No. The CVSS vector specifies a local attack vector requiring low privileges — this is a local kernel memory-corruption flaw, not a remotely reachable one.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which kernel versions fix this? Our source data carries no single fixed-version field. Consult the upstream kernel fix commits linked from NVD’s record, or your Linux distribution’s own security errata, for the specific version that includes the fix.


Severity, weakness classification, and mechanism sourced from the National Vulnerability Database record for CVE-2026-46331 and the linked upstream Linux kernel fix commit. Exploitation status and the August 26, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Cross-referenced intelligence


Analyst tools