PT-2026-35141 · Linux · Linux Kernel
Published
2026-04-25
·
Updated
2026-05-26
·
CVE-2026-31681
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the netfilter
xt multiport component where the checkentry path fails to validate range encoding. The ports match v1() function treats any non-zero pflags entry as the start of a port range and automatically consumes the subsequent ports[] element as the range end. Because the validation process does not verify the range encoding, malformed rules can designate the final slot as a range start or place two range starts consecutively. This allows ports match v1() to read beyond the last valid ports[] element while interpreting the rule.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel