Skip to main content
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryopen-source-dependency-vulnerability

Microsoft Discloses Broad Set of Linux Kernel Vulnerabilities

Updated 26d agoFirst seen Apr 30, 202624 sources

Microsoft published a broad batch of Security Update Guide entries for Linux kernel flaws affecting memory management, networking, virtualization, device drivers, and subsystem input validation. The listed issues include use-after-free, NULL dereference, integer underflow, refcount underflow, information disclosure, and bounds-checking failures tracked as CVE-2026-31496, CVE-2026-31458, CVE-2026-31689, CVE-2026-31615, CVE-2026-31664, CVE-2026-31656, CVE-2026-31611, CVE-2026-31671, CVE-2026-31612, and others. Affected components span nf_conntrack_expect, damon, edac_mc, renesas_usb3, xfrm, drm/i915, ksmbd, stmmac, tipc, mptcp, NFC, HID, KVM, mmc, x86/CPU, PCI endpoint, blk-cgroup, media/as102, and altera-tse.

Several entries point to bugs that could lead to kernel crashes, memory corruption, or data leakage if triggered through malformed input, protocol handling, or device interaction. Notable examples include a slab use-after-free in mptcp, information leaks in xfrm_user and xfrm, validation flaws in ksmbd, endpoint index handling in usb: gadget: renesas_usb3, and multiple underflow and teardown-ordering bugs across networking and driver code. The disclosures indicate a coordinated publication of upstream Linux kernel fixes through Microsoft's advisory channel, underscoring the need for organizations running Linux workloads in Microsoft-connected environments to review affected kernel versions and apply vendor patches promptly.

Share:
Microsoft Discloses Broad Set of Linux Kernel Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 29, 202630d ago

Microsoft publishes CVE-2026-31689 advisory

Microsoft added CVE-2026-31689 to its Security Update Guide, describing a Linux kernel EDAC/mc issue involving error-path ordering in edac_mc_alloc().

Apr 26, 20261mo ago

Microsoft publishes batch of Linux kernel CVE advisories

Microsoft published a large set of Security Update Guide entries for Linux kernel vulnerabilities, including issues in USB, xfrm, ksmbd, networking, HID, KVM, MMC, PCI, memory management, media, and CPU components. The disclosures include CVE-2026-31578, CVE-2026-31586, CVE-2026-31588, CVE-2026-31594, CVE-2026-31611, CVE-2026-31612, CVE-2026-31615, CVE-2026-31622, CVE-2026-31624, CVE-2026-31628, CVE-2026-31649, CVE-2026-31651, CVE-2026-31656, CVE-2026-31658, CVE-2026-31662, CVE-2026-31664, CVE-2026-31669, and CVE-2026-31671.

Apr 23, 20261mo ago

Microsoft publishes CVE-2026-31496 advisory

Microsoft added CVE-2026-31496 to its Security Update Guide, covering a Linux kernel netfilter nf_conntrack_expect issue related to skipping expectations across network namespaces via proc.

Microsoft publishes CVE-2026-31458 advisory

Microsoft added CVE-2026-31458 to its Security Update Guide, describing a Linux kernel issue in mm/damon/sysfs involving access to contexts_arr[0] without checking contexts->nr first.

SOURCE COVERAGE

Sources

24 references tracked. Mallory keeps watching after this page renders.

24 SOURCESView all
Msrc Security AdvisoriesAdvisories
Apr 29, 2026

CVE-2026-31689 - Security Update Guide - Microsoft - EDAC/mc: Fix error path ordering in edac_mc_alloc()

msrc.microsoft.com

Open source
Msrc Security AdvisoriesAdvisories
Apr 26, 2026

CVE-2026-31656 - Security Update Guide - Microsoft - drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat

msrc.microsoft.com

Open source
Msrc Security AdvisoriesAdvisories
Apr 26, 2026

CVE-2026-31669 - Security Update Guide - Microsoft - mptcp: fix slab-use-after-free in __inet_lookup_established

msrc.microsoft.com

Open source
Msrc Security AdvisoriesAdvisories
Apr 26, 2026

CVE-2026-31671 - Security Update Guide - Microsoft - xfrm_user: fix info leak in build_report()

msrc.microsoft.com

Open source
16 additional sources from 26-04-2026 to 26-04-2026
Msrc Security AdvisoriesAdvisories
Apr 26, 2026

CVE-2026-31655 - Security Update Guide - Microsoft - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled

msrc.microsoft.com

Open source
Msrc Security AdvisoriesAdvisories
Apr 26, 2026

CVE-2026-31664 - Security Update Guide - Microsoft - xfrm: clear trailing padding in build_polexpire()

msrc.microsoft.com

Open source
Msrc Security AdvisoriesAdvisories
Apr 23, 2026

CVE-2026-31496 - Security Update Guide - Microsoft - netfilter: nf_conntrack_expect: skip expectations in other netns via proc

msrc.microsoft.com

Open source
Msrc Security AdvisoriesAdvisories
Apr 23, 2026

CVE-2026-31458 - Security Update Guide - Microsoft - mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0]

msrc.microsoft.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Discloses Broad Set of Linux Kernel Vulnerabilities | Mallory