
Passive Linux host vulnerability scanner for CVE-2026-31694: checks running kernel, FUSE config, package metadata, and patch evidence, then generates tailored mitigation guidance.
A passive Linux host assessment tool for CVE-2026-31694, a FUSE readdir-cache out-of-bounds write in the Linux kernel.
The scanner evaluates the running kernel, FUSE exposure, local package metadata, kernel source evidence, execution environment, and operating-system family. When the host may be affected, it produces a mitigation guide tailored to the detected distribution.
Author: Aung Myat Thu [w01f]
cve_2026_31694_scanner.py is a local, non-exploit vulnerability assessment utility.
It does not confirm the vulnerability by triggering the affected FUSE code path. Instead, it combines multiple passive indicators:
CONFIG_FUSE_FS kernel configuration;/dev/fuse presence and current-user access;The result is an exposure assessment, not an exploit-based proof.
CVE-2026-31694 affects the Linux kernel FUSE readdir cache.
The vulnerable logic calculates the serialized size of a directory entry from a server-controlled name length and copies the record into a single page-cache page. A directory entry with a name length of 4095 can produce a serialized size of 4120 bytes.
On a system using 4096-byte pages, that record exceeds one page by 24 bytes.
The upstream correction rejects directory records that cannot fit inside a single page before the cache copy occurs.
fs/fuse/readdir.c
fuse_add_dirent_to_cache()
The scanner contains the following upstream stable fixed baselines:
| Kernel series | Fixed baseline |
|---|---|
| 5.10 | 5.10.258 |
| 5.15 | 5.15.209 |
| 6.1 | 6.1.175 |
| 6.6 | 6.6.136 |
| 6.12 | 6.12.84 |
| 6.18 | 6.18.25 |
| 7.0 | 7.0.2 |
| Mainline | 7.1 or newer |
These versions are used as one assessment input. They are not treated as the only source of truth because distribution vendors may backport the correction while retaining an older upstream version number.
The scanner is designed to avoid invoking the vulnerable operation.
/dev/fuse;/etc/passwd;/dev/fuse permissions;/proc, /boot, /lib/modules, /usr/lib/modules, /usr/src, and package metadata directories;--output is explicitly supplied;Mitigation commands are documentation output. They are never executed automatically.
platform.release() and parses the upstream-style kernel version./etc/os-release or /usr/lib/os-release.CONFIG_FUSE_FS from available kernel configuration sources./proc/filesystems./dev/fuse metadata and current-user read/write access.fusermount3 or fusermount./proc/self/mountinfo.CVE-2026-31694;/var/run/reboot-required where applicable.systemd-detect-virt when available.The scanner uses only the Python standard library.
Additional evidence is collected when the following tools are present:
| Tool | Purpose |
|---|---|
dpkg-query | Debian/Ubuntu kernel package ownership and changelog discovery |
rpm | Fedora/RHEL/SUSE package ownership and changelog inspection |
pacman | Arch-family kernel package and update metadata |
apt | Debian-family cached update query |
dnf or dnf5 | Fedora/RHEL cached update query |
zypper | SUSE cached CVE patch query |
apk | Alpine package/update query |
systemd-detect-virt | Container and virtual-machine detection |
Root privileges are not required for the normal scan.
Some evidence may be unavailable to an unprivileged account because of system-specific file permissions.
Place the scanner in a working directory:
chmod +x cve_2026_31694_scanner.py
Run it directly:
./cve_2026_31694_scanner.py
Or invoke it with Python:
python3 cve_2026_31694_scanner.py
No Python package installation is required.
python3 cve_2026_31694_scanner.py
python3 cve_2026_31694_scanner.py --format json
The compatibility alias below produces the same format:
python3 cve_2026_31694_scanner.py --json
python3 cve_2026_31694_scanner.py --format markdown
python3 cve_2026_31694_scanner.py \
--format markdown \
--output cve-2026-31694-report.md
python3 cve_2026_31694_scanner.py --mitigation-only
python3 cve_2026_31694_scanner.py --no-package-query
python3 cve_2026_31694_scanner.py --no-exit-status