SB2026041425 - Incorrect calculation in Linux kernel netfilter
Published: April 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2026-31416)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper calculation of netlink header size in nfnetlink_log when processing netlink messages. A local user can send a specially crafted netlink message to cause a denial of service.
The issue results in a kernel warning and the affected netlink message being dropped, with no other explicitly stated effects.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/607245c4dbb86d9a10dd8388da0fb82170a99b61
- https://git.kernel.org/stable/c/6b419700e459fbf707ca1543b7c1b57a60fedb73
- https://git.kernel.org/stable/c/6d52a4a0520a6696bdde51caa11f2d6821cd0c01
- https://git.kernel.org/stable/c/761b45c661af48da6a065868d59ab1e1f64fd9b6
- https://git.kernel.org/stable/c/88a8f56e6276f616baad4274c6b8e4683e26e520
- https://git.kernel.org/stable/c/f08ffa3e1c8e36b6131f69c5eb23700c28cbd262