news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-31681

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
6.1 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
EPSS
0.12%
Risk score
1.0
Published
2026-04-25
Status
Published

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the start of a port range and unconditionally consumes the next ports[] element as the range end. The checkentry path currently validates protocol, flags and count, but it does not validate the range encoding itself. As a result, malformed rules can mark the last slot as a range start or place two range starts back to back, leaving ports_match_v1() to step past the last valid ports[] element while interpreting the rule. Reject malformed multiport v1 rules in checkentry by validating that each range start has a following element and that the following element is not itself marked as another range start. A flaw was found in the Linux kernel's netfilter xt_multiport module. This vulnerability arises from insufficient validation of range encoding within the `checkentry` function. A local attacker can exploit this by crafting malformed multiport rules, which causes the `ports_match_v1()` function to read beyond its intended memory boundary. This out-of-bounds read can lead to a denial of service (DoS) or potentially disclose sensitive information.

Weaknesses

CWE-125

Coverage 5

Advisories and references