CVE-2026-31416
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink header size This is a followup to an old bug fix: NLMSG_DONE needs to account for the netlink header size, not just the attribute size. This can result in a WARN splat + drop of the netlink message, but other than this there are no ill effects.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 6.1.170-1 |
| debian | bullseye | fixed | 6.1.170-1~deb11u1 |
| debian | forky | fixed | 6.19.12-1 |
| debian | sid | fixed | 6.19.12-1 |
| debian | trixie | fixed | 6.12.85-1 |
| linux-kernel | affected | 3.11 | |
| linux-kernel | 7.0 | affected | |
References
- https://git.kernel.org/stable/c/09883bf257f4243ed5a1fd35078ec6f0d0f3696a
- https://git.kernel.org/stable/c/4ec216410fac9de83c99177a160ebb8d42fad075
- https://git.kernel.org/stable/c/607245c4dbb86d9a10dd8388da0fb82170a99b61
- https://git.kernel.org/stable/c/6b419700e459fbf707ca1543b7c1b57a60fedb73
- https://git.kernel.org/stable/c/6d52a4a0520a6696bdde51caa11f2d6821cd0c01
- https://git.kernel.org/stable/c/761b45c661af48da6a065868d59ab1e1f64fd9b6
- https://git.kernel.org/stable/c/88a8f56e6276f616baad4274c6b8e4683e26e520
- https://git.kernel.org/stable/c/f08ffa3e1c8e36b6131f69c5eb23700c28cbd262
- https://www.suse.com/security/cve/CVE-2026-31416.html
- https://security-tracker.debian.org/tracker/CVE-2026-31416
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.