CVE-2026-31407
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports out-of-bounds access in sctp and ctnetlink. These attributes are used by the kernel without any validation. Extend the netlink policies accordingly. Quoting the reporter: nlattr_to_sctp() assigns the user-supplied CTA_PROTOINFO_SCTP_STATE value directly to ct->proto.sctp.state without checking that it is within the valid range. [..] and: ... with exp->dir = 100, the access at ct->master->tuplehash[100] reads 5600 bytes past the start of a 320-byte nf_conn object, causing a slab-out-of-bounds read confirmed by UBSAN.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | affected | |
| debian | bullseye | affected | |
| debian | forky | fixed | 6.19.10-1 |
| debian | sid | fixed | 6.19.10-1 |
| debian | trixie | fixed | 6.12.85-1 |
| linux-kernel | affected | 6.6.136 | |
| linux-kernel | 7.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| gcp | | |
References
- https://git.kernel.org/stable/c/0fbae1e74493d5a160a70c51aeba035d8266ea7d
- https://git.kernel.org/stable/c/67c53c1978cef3c504237275e39c857e2f6af56e
- https://git.kernel.org/stable/c/9174d28f3f15d8c4962f5980c0be167633880443
- https://git.kernel.org/stable/c/c5e918390002edf0cff80a0e7ce1f86f16a9507c
- https://git.kernel.org/stable/c/f900e1d77ee0ef87bfb5ab3fe60f0b3d8ad5ba05
- https://www.suse.com/security/cve/CVE-2026-31407.html
- https://security-tracker.debian.org/tracker/CVE-2026-31407
- https://git.kernel.org/stable/c/78bba9f73942aa7dca47d817d8cec0fb9b443b70
- https://git.kernel.org/stable/c/be88a337bf07afb1ee173f1099294d1b7ab3fefe
- https://git.kernel.org/stable/c/e7b5766693477c52424cc6c79dd30a7a9c7db52c
CWEs
CWE-787
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.