PT-2026-32344 · Linux · Linux Kernel

Published

2026-04-13

·

Updated

2026-05-26

·

CVE-2026-31418

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the netfilter ipset component where the mtype del() function fails to drop logically empty buckets. The function counts empty slots below n->pos in k, but only drops the bucket when both n->pos and k are zero. This results in buckets not being released when all live entries are removed while n->pos still points past deleted slots.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-31418
ECHO-DFAB-9B18-1D6D
OESA-2026-2232
OESA-2026-2235
OESA-2026-2236

Affected Products

Linux Kernel