Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE_2026_31694 — Passive Linux host vulnerability scanner for CVE-2026-31694: checks running kernel, FUSE config, package metadata, and patch evidence, then generates tailored mitigation guidance. | Kitploit
Tools/GitHubGitHub/zenzue/cve_2026_31694
Defensive ToolsVulnerability ScannersVulnerability AnalysisConfiguration Auditing
GitHubzenzue/cve_2026_31694

CVE_2026_31694

Passive Linux host vulnerability scanner for CVE-2026-31694: checks running kernel, FUSE config, package metadata, and patch evidence, then generates tailored mitigation guidance.

View Repository
132 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31694 Passive Scanner

A passive Linux host assessment tool for CVE-2026-31694, a FUSE readdir-cache out-of-bounds write in the Linux kernel.

The scanner evaluates the running kernel, FUSE exposure, local package metadata, kernel source evidence, execution environment, and operating-system family. When the host may be affected, it produces a mitigation guide tailored to the detected distribution.

Author: Aung Myat Thu [w01f]


Table of Contents

  • Overview
  • Vulnerability Summary
  • Security Model
  • Features
  • Requirements
  • Installation
  • Usage
  • Command-Line Options
  • Assessment Workflow
  • Verdicts
  • Exit Codes
  • Detection Sources
  • Distribution Support
  • Mitigation Generation
  • Container and WSL Behavior
  • Report Formats
  • Automation and Integration
  • Operational Guidance
  • Limitations
  • Troubleshooting
  • References

Overview

cve_2026_31694_scanner.py is a local, non-exploit vulnerability assessment utility.

It does not confirm the vulnerability by triggering the affected FUSE code path. Instead, it combines multiple passive indicators:

  • running kernel release;
  • upstream fixed-version baselines;
  • current memory page size;
  • CONFIG_FUSE_FS kernel configuration;
  • registered FUSE filesystem types;
  • /dev/fuse presence and current-user access;
  • FUSE mount helper availability;
  • active FUSE mounts;
  • installed kernel source inspection;
  • kernel package ownership;
  • local package changelog evidence;
  • cached package update metadata;
  • installed-versus-running kernel comparison;
  • distribution and package-manager detection;
  • container, virtual-machine, and WSL detection.

The result is an exposure assessment, not an exploit-based proof.


Vulnerability Summary

CVE-2026-31694 affects the Linux kernel FUSE readdir cache.

The vulnerable logic calculates the serialized size of a directory entry from a server-controlled name length and copies the record into a single page-cache page. A directory entry with a name length of 4095 can produce a serialized size of 4120 bytes.

On a system using 4096-byte pages, that record exceeds one page by 24 bytes.

The upstream correction rejects directory records that cannot fit inside a single page before the cache copy occurs.

Affected component

fs/fuse/readdir.c
fuse_add_dirent_to_cache()

Scanner baseline data

The scanner contains the following upstream stable fixed baselines:

Kernel seriesFixed baseline
5.105.10.258
5.155.15.209
6.16.1.175
6.66.6.136
6.126.12.84
6.186.18.25
7.07.0.2
Mainline7.1 or newer

These versions are used as one assessment input. They are not treated as the only source of truth because distribution vendors may backport the correction while retaining an older upstream version number.


Security Model

The scanner is designed to avoid invoking the vulnerable operation.

The scanner does not

  • mount a FUSE filesystem;
  • open or communicate with /dev/fuse;
  • start a FUSE server;
  • submit crafted directory records;
  • allocate memory for page-placement testing;
  • groom kernel allocators;
  • modify /etc/passwd;
  • change kernel configuration;
  • load or unload kernel modules;
  • modify /dev/fuse permissions;
  • install or remove packages;
  • reboot the system;
  • attempt privilege escalation.

The scanner may

  • read files under /proc, /boot, /lib/modules, /usr/lib/modules, /usr/src, and package metadata directories;
  • execute bounded, read-only package queries;
  • inspect active mounts and filesystem registration;
  • write a report only when --output is explicitly supplied;
  • print mitigation commands for administrator review.

Mitigation commands are documentation output. They are never executed automatically.


Features

Host and kernel identification

  • Reads platform.release() and parses the upstream-style kernel version.
  • Reads /etc/os-release or /usr/lib/os-release.
  • Detects CPU architecture and memory page size.
  • Identifies whether the scanned kernel belongs to the current operating system.

FUSE exposure assessment

  • Reads CONFIG_FUSE_FS from available kernel configuration sources.
  • Detects built-in FUSE support and loadable-module configurations.
  • Reads /proc/filesystems.
  • Checks /dev/fuse metadata and current-user read/write access.
  • Locates fusermount3 or fusermount.
  • Parses active FUSE mounts from /proc/self/mountinfo.

Patch evidence

  • Compares the running version against upstream fixed baselines.
  • Searches installed kernel source for the oversized-record guard.
  • Checks local RPM or Debian package changelogs for:
    • CVE-2026-31694;
    • the upstream patch title.

Package and reboot state

  • Attempts to identify the package owning the running kernel.
  • Queries local package-manager metadata without refreshing repositories.
  • Detects a newer installed kernel when the host environment is authoritative.
  • Checks /var/run/reboot-required where applicable.

Environment awareness

  • Detects Docker-compatible containers.
  • Detects Podman-compatible containers.
  • Detects container-related cgroups.
  • Detects WSL.
  • Detects virtual machines using systemd-detect-virt when available.

Reporting

  • Human-readable text output.
  • Machine-readable JSON output.
  • Markdown report output.
  • Mitigation-only output.
  • Optional file output.
  • Meaningful process exit codes.

Requirements

Required

  • Linux for kernel assessment.
  • Python 3.9 or newer.
  • Read access to normal system metadata.

The scanner uses only the Python standard library.

Optional commands

Additional evidence is collected when the following tools are present:

ToolPurpose
dpkg-queryDebian/Ubuntu kernel package ownership and changelog discovery
rpmFedora/RHEL/SUSE package ownership and changelog inspection
pacmanArch-family kernel package and update metadata
aptDebian-family cached update query
dnf or dnf5Fedora/RHEL cached update query
zypperSUSE cached CVE patch query
apkAlpine package/update query
systemd-detect-virtContainer and virtual-machine detection

Root privileges are not required for the normal scan.

Some evidence may be unavailable to an unprivileged account because of system-specific file permissions.


Installation

Place the scanner in a working directory:

chmod +x cve_2026_31694_scanner.py

Run it directly:

./cve_2026_31694_scanner.py

Or invoke it with Python:

python3 cve_2026_31694_scanner.py

No Python package installation is required.


Usage

Standard assessment

python3 cve_2026_31694_scanner.py

JSON output

python3 cve_2026_31694_scanner.py --format json

The compatibility alias below produces the same format:

python3 cve_2026_31694_scanner.py --json

Markdown report

python3 cve_2026_31694_scanner.py --format markdown

Save a report

python3 cve_2026_31694_scanner.py \
  --format markdown \
  --output cve-2026-31694-report.md

Print only remediation guidance

python3 cve_2026_31694_scanner.py --mitigation-only

Skip package update queries

python3 cve_2026_31694_scanner.py --no-package-query

Always return success after reporting

python3 cve_2026_31694_scanner.py --no-exit-status
Download Tool