Junglewise Threat Intelligence

CVE-2026-31407: Linux Kernel out-of-bounds access in Netfilter conntrack

CVE-2026-31407 · Severity: high · CVSS 7.1 · Published 2026-04-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system crash or potentially access sensitive kernel memory. The issue exists in the Netfilter component, which manages network connections and firewall rules. By sending specially crafted network configuration messages, an attacker can trigger an out-of-bounds memory access, leading to instability or information disclosure.

Technical details

An out-of-bounds access vulnerability exists in the Linux kernel's netfilter conntrack component (specifically in sctp and ctnetlink). The root cause is the lack of validation for user-supplied Netlink attributes; specifically, nlattr_to_sctp() assigns CTA_PROTOINFO_SCTP_STATE values directly to internal structures without range checking. Additionally, an unvalidated 'exp->dir' value can lead to a slab-out-of-bounds read in ct->master->tuplehash. A local attacker with sufficient privileges to interact with Netlink can exploit this to read kernel memory or cause a denial of service (system crash). The issue has been resolved by extending Netlink policies to include proper maximum value validations.

Affected products

  • Linux Linux Kernel 2.6.27 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.10, 7.0-rc1 to 7.0-rc4

Timeline

  • 2026-03-10: other: Vulnerability fixed in upstream commits
  • 2026-04-06: disclosed: Initial publication of CVE-2026-31407
  • 2026-04-06: advisory

References

Related threats