CVE-2026-31786 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor a string. The first causes a buffer overflow as sprintf in buildid_show will read and copy till it finds a NUL. 00000000 f4 91 51 f4 dd 38 9e 9d 65 47 52 eb 10 71 db 50 |..Q..8..eGR..q.P| 00000010 b9 a8 01 42 6f 2e 32 |...Bo.2| 00000017 So use a memcpy instead of sprintf to have the correct value: 00000000 f4 91 51 f4 dd 00 9e 9d 65 47 52 eb 10 71 db 50 |..Q.....eGR..q.P| 00000010 b9 a8 01 42 |...B| 00000014 (the above have a hack to embed a zero inside and check it's returned correctly). This is XSA-485 / CVE-2026-31786
A buffer overflow vulnerability has been identified in the Linux kernel within the Xen hypervisor interface. This issue arises in the sysfs file '/sys/hypervisor/properties/buildid', which contains a binary build ID from the hypervisor that is not properly null-terminated. The kernel driver uses 'sprintf' to write this data to a user-readable buffer, leading to a potential out-of-bounds read. In some cases, this could even allow writing past the 4KB sysfs buffer limit, possibly overwriting kernel memory or leaking sensitive information.
The vulnerability has been patched in the Linux kernel. The patch is available in the official Linux Git repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/27fdbab4221b375de54bf91919798d88520c6e28 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4b4defd2fce3f966c25adabf46644a85558f1169 | kernel.org | Patch |
| https://git.kernel.org/stable/c/52cecff98bda2c51eed1c6ce9d21c5d6268fb19d | kernel.org | Patch |
| https://git.kernel.org/stable/c/5c5ff7c7bd15bb536f44b10b3fb5b8408f344d0a | kernel.org | Patch |
| https://git.kernel.org/stable/c/8288d031a01dbacfde3fc643f7be3d23504de64d | kernel.org | Patch |
| https://git.kernel.org/stable/c/d5f59216650c51e5e3fcb7517c825bc8047f60ef | kernel.org | Patch |
| https://git.kernel.org/stable/c/e3af585e1728c917682b6a3de9a69b41fb9194d4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f458ba102da97fafca106327086fc95f3fc764cb | kernel.org | Patch |
| http://www.openwall.com/lists/oss-security/2026/04/28/12 | CVE | Mailing ListThird Party Advisory |
| http://xenbits.xen.org/xsa/advisory-485.html | CVE | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.13, < 5.10.254 >= 5.11, < 5.15.204 >= 5.16, < 6.1.170 >= 6.2, < 6.6.137 >= 6.7, < 6.12.85 >= 6.13, < 6.18.26 >= 6.19, < 7.0.3 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 6, 2026 | Initial Analysis | [email protected] |
| May 4, 2026 | CVE Modified | kernel.org |
| May 3, 2026 | CVE Modified | kernel.org |
| Apr 30, 2026 | New CVE Received | kernel.org |
| Apr 30, 2026 | CVE Modified | CVE |