news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-31416

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.5 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.12%
Risk score
1.1
Published
2026-04-13
Status
Published

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink header size This is a followup to an old bug fix: NLMSG_DONE needs to account for the netlink header size, not just the attribute size. This can result in a WARN splat + drop of the netlink message, but other than this there are no ill effects. A flaw was found in the Linux kernel's netfilter subsystem, specifically within `nfnetlink_log`. A local user could exploit this vulnerability by sending a crafted netlink message that causes an incorrect accounting of the netlink header size. This miscalculation can lead to a Denial of Service (DoS), resulting in a warning message and the dropping of the netlink message.

Weaknesses

CWE-131

Coverage 6

Advisories and references