CVE-2026-31416

high

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink header size This is a followup to an old bug fix: NLMSG_DONE needs to account for the netlink header size, not just the attribute size. This can result in a WARN splat + drop of the netlink message, but other than this there are no ill effects.

References

https://git.kernel.org/stable/c/f08ffa3e1c8e36b6131f69c5eb23700c28cbd262

https://git.kernel.org/stable/c/88a8f56e6276f616baad4274c6b8e4683e26e520

https://git.kernel.org/stable/c/761b45c661af48da6a065868d59ab1e1f64fd9b6

https://git.kernel.org/stable/c/6d52a4a0520a6696bdde51caa11f2d6821cd0c01

https://git.kernel.org/stable/c/6b419700e459fbf707ca1543b7c1b57a60fedb73

https://git.kernel.org/stable/c/607245c4dbb86d9a10dd8388da0fb82170a99b61

Details

Source: Mitre, NVD

Published: 2026-04-13

Updated: 2026-04-13

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00024