PT-2026-30575 · Linux · Linux Kernel

Hyunwoo Kim

·

Published

2026-04-06

·

Updated

2026-05-20

·

CVE-2026-31407

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in its netfilter component related to conntrack and missing netlink policy validations. Specifically, the nlattr to sctp() function improperly handles user-supplied CTA PROTOINFO SCTP STATE values, potentially leading to an out-of-bounds access. This issue can occur when processing netlink attributes without proper validation, resulting in a slab-out-of-bounds read. The vulnerability affects the ctnetlink functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-05099
CVE-2026-31407
ECHO-822E-A5C8-1E1E
OESA-2026-2232
OESA-2026-2235
OESA-2026-2236

Affected Products

Linux Kernel