cbcvebase.
CVE-2026-31407
published 2026-04-06

CVE-2026-31407: In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports…

PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.17%
6.6th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports out-of-bounds access in sctp and ctnetlink. These attributes are used by the kernel without any validation. Extend the netlink policies accordingly. Quoting the reporter: nlattr_to_sctp() assigns the user-supplied CTA_PROTOINFO_SCTP_STATE value directly to ct->proto.sctp.state without checking that it is within the valid range. [..] and: ... with exp->dir = 100, the access at ct->master->tuplehash[100] reads 5600 bytes past the start of a 320-byte nf_conn object, causing a slab-out-of-bounds read confirmed by UBSAN.

Affected

57 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < e7b5766693477c52424cc6c79dd30a7a9c7db52ce7b5766693477c52424cc6c79dd30a7a9c7db52c
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < 78bba9f73942aa7dca47d817d8cec0fb9b443b7078bba9f73942aa7dca47d817d8cec0fb9b443b70
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < be88a337bf07afb1ee173f1099294d1b7ab3fefebe88a337bf07afb1ee173f1099294d1b7ab3fefe
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < c5e918390002edf0cff80a0e7ce1f86f16a9507cc5e918390002edf0cff80a0e7ce1f86f16a9507c
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < 9174d28f3f15d8c4962f5980c0be1676338804439174d28f3f15d8c4962f5980c0be167633880443
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < 67c53c1978cef3c504237275e39c857e2f6af56e67c53c1978cef3c504237275e39c857e2f6af56e
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < 0fbae1e74493d5a160a70c51aeba035d8266ea7d0fbae1e74493d5a160a70c51aeba035d8266ea7d
linuxlinux>= a258860e01b80e8f554a4ab1a6c95e6042eb8b73 < f900e1d77ee0ef87bfb5ab3fe60f0b3d8ad5ba05f900e1d77ee0ef87bfb5ab3fe60f0b3d8ad5ba05
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 2.6.27 < 6.6.1366.6.136
linuxlinux_kernel>= 6.13 < 6.18.246.18.24
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.7 < 6.12.836.12.83
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
vendor_msrc7.1HIGH
vendor_ubuntu7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.