CVE-2026-31416
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink header size This is a followup to an old bug fix: NLMSG_DONE needs to account for the netlink header size, not just the attribute size.
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink header size This is a followup to an old bug fix: NLMSG_DONE needs to account for the netlink header size, not just the attribute size. This can result in a WARN splat + drop of the netlink message, but other than this there are no ill effects.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/09883bf257f4243ed5a1fd35078ec6f0d0f3696aPatch
- https://git.kernel.org/stable/c/4ec216410fac9de83c99177a160ebb8d42fad075Patch
- https://git.kernel.org/stable/c/607245c4dbb86d9a10dd8388da0fb82170a99b61Patch
- https://git.kernel.org/stable/c/6b419700e459fbf707ca1543b7c1b57a60fedb73Patch
- https://git.kernel.org/stable/c/6d52a4a0520a6696bdde51caa11f2d6821cd0c01Patch
- https://git.kernel.org/stable/c/761b45c661af48da6a065868d59ab1e1f64fd9b6Patch
- https://git.kernel.org/stable/c/88a8f56e6276f616baad4274c6b8e4683e26e520Patch
- https://git.kernel.org/stable/c/f08ffa3e1c8e36b6131f69c5eb23700c28cbd262Patch
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.