CVE-2026-31635 carries a CVSS 3.1 base score of 7.5 against the Linux kernel. NVD classifies it as CWE-130 (Improper Handling of Length Parameter Inconsistency). VulnCheck’s KEV feed reports the CVE as exploited, dated August 26, 2026, and titles its entry a “Linux Kernel ‘rxgk’ Local Privilege Escalation.”
That exploitation report is single-sourced. CISA has not added CVE-2026-31635 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description, sourced from the upstream kernel fix commit, locates the bug in the kernel’s rxrpc networking protocol implementation, specifically its rxgk security-class response-authentication code. NVD states the function responsible for verifying an incoming response packet’s authenticator length has an inverted length check: it’s supposed to reject an authenticator that claims to be larger than the actual remaining packet data, but the existing logic does the opposite, accepting oversized values and passing them to a decryption routine that can then be driven into an assertion failure by an internally impossible length value.
We are reporting the nature of this inverted check and its consequence rather than the specific packet construction needed to trigger it, which is available in the upstream kernel commit NVD cites for readers who need it for patch verification.
Evidence and confidence
- Medium confidence — the CVSS 7.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), the CWE-130 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by the upstream kernel fix commits NVD links. The exploitation report traces to VulnCheck KEV alone. - Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00923, a 58.6th percentile score as of our ingestion.
No field is in conflict between our two sources. Our data carries no single fixed-version field; the upstream kernel commits NVD links identify the corrected code.
Why this matters
This CVE’s CVSS vector differs notably from VulnCheck’s own “local privilege escalation” characterization: NVD’s vector marks the attack vector network-reachable (AV:N) with an availability-only impact (A:H, no confidentiality or integrity impact), consistent with a remotely triggerable kernel crash (denial of service) in the rxrpc protocol handler rather than a local-only privilege-escalation primitive. We report both characterizations rather than resolving the discrepancy: NVD’s own technical vector points to a network-facing crash condition, while VulnCheck’s title suggests a broader local privilege-escalation use.
rxrpc is a legacy protocol historically associated with AFS (Andrew File System) and Kerberos-based authentication in specific enterprise and academic Linux environments — a narrower deployment footprint than a general-purpose kernel networking path, but one where a kernel crash triggerable by a malformed response packet is still a meaningful denial-of-service risk for any system running the protocol.
Frequently Asked Questions
What is CVE-2026-31635?
A CVSS 7.5 vulnerability (CWE-130) in the Linux kernel’s rxrpc/rxgk network protocol implementation, caused by an inverted authenticator-length check that allows an oversized value to reach a decryption routine and trigger a kernel assertion failure.
Is CVE-2026-31635 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 26, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Is this a remote or local vulnerability?
NVD’s own CVSS vector marks it network-reachable (AV:N), while VulnCheck’s KEV entry titles it a local privilege escalation. We report this discrepancy rather than resolving it in either direction.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which kernel versions fix this? Our source data carries no single fixed-version field. Consult the upstream kernel fix commits linked from NVD’s record for the specific version that includes the fix.
Severity, weakness classification, and mechanism sourced from the National Vulnerability Database record for CVE-2026-31635 and the linked upstream Linux kernel fix commit. Exploitation status, the August 26, 2026 catalog date, and the local-privilege-escalation characterization reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.