Improper input validation in Linux kernel - CVE-2026-31472
Published: April 24, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in __input_process_payload() when processing decrypted IPTFS payloads. A remote attacker can send a crafted ESP packet containing a malformed inner IPv4 header to cause a denial of service.
The issue can trigger an infinite loop in softirq context when the inner IPv4 header has tot_len set to 0 or otherwise invalid length fields.