CVE-2026-31742
Last modified
CVE-2026-31742 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: vt: discard stale unicode buffer on alt screen exit after resize When enter_alt_screen() saves vc_uni_lines into vc_saved_uni_lines and sets vc_uni_lines to NULL, a subsequent console resize via vc_do_resize() skips reallocating the unicode buffer because vc_uni_lines is NULL. However, vc_saved_uni_lines still points to the old buffer allocated for the original dimensions. When leave_alt_screen() later restores vc_saved_uni_lines, the buffer dimensions no longer match vc_rows/vc_cols. Any operation that iterates over the unicode buffer using the current dimensions (e.g. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: vt: discard stale unicode buffer on alt screen exit after resize When enter_alt_screen() saves vc_uni_lines into vc_saved_uni_lines and sets vc_uni_lines to NULL, a subsequent console resize via vc_do_resize() skips reallocating the unicode buffer because vc_uni_lines is NULL. However, vc_saved_uni_lines still points to the old buffer allocated for the original dimensions. When leave_alt_screen() later restores vc_saved_uni_lines, the buffer dimensions no longer match vc_rows/vc_cols. Any operation that iterates over the unicode buffer using the current dimensions (e.g. csi_J clearing the screen) will access memory out of bounds, causing a kernel oops: BUG: unable to handle page fault for address: 0x0000002000000020 RIP: 0010:csi_J+0x133/0x2d0 The faulting address 0x0000002000000020 is two adjacent u32 space characters (0x20) interpreted as a pointer, read from the row data area past the end of the 25-entry pointer array in a buffer allocated for 80x25 but accessed with 240x67 dimensions. Fix this by checking whether the console dimensions changed while in the alternate screen. If they did, free the stale saved buffer instead of restoring it. The unicode screen will be lazily rebuilt via vc_uniscr_check() when next needed.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 6.18.20, < 6.18.22 | — |
| Linux | Linux Kernel | >= 6.19.10, < 6.19.12 | — |
| Linux | Linux Kernel | 7.0 | Rc5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-31742?
How severe is CVE-2026-31742?
How do I fix CVE-2026-31742?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-31736In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31737In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31738In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31739In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-31740In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31741In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31743In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-31744In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31745In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-31746In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-31747In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-31748In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-31742?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
