{"id":"CVE-2026-31416","title":"netfilter: nfnetlink_log: account for netlink header size","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: account for netlink header size\n\nThis is a followup to an old bug fix: NLMSG_DONE needs to account\nfor the netlink header size, not just the a…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 4ec216410fac9de83c99177a160ebb8d42fad075","Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 09883bf257f4243ed5a1fd35078ec6f0d0f3696a","Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 761b45c661af48da6a065868d59ab1e1f64fd9b6","Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 607245c4dbb86d9a10dd8388da0fb82170a99b61","Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 6b419700e459fbf707ca1543b7c1b57a60fedb73","Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 88a8f56e6276f616baad4274c6b8e4683e26e520","Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < f08ffa3e1c8e36b6131f69c5eb23700c28cbd262","Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 6d52a4a0520a6696bdde51caa11f2d6821cd0c01","Linux 3a758a2b78da2f49f7165678faf999e946a0c4b5","Linux 131172845aa2c804ffa9423455aee585061ea35e","Linux b1fef6b81871a396f3b8702077333e769673c87b","Linux add9183d993c12fb61ce0a674a424341d5be5b36","Linux >= 3.10.61 < 3.11","Linux >= 3.12.34 < 3.13","Linux >= 3.14.25 < 3.15","Linux >= 3.17.4 < 3.18","Linux 3.18"],"published":"2026-04-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:46:52.211Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31416","references":[{"url":"https://git.kernel.org/stable/c/4ec216410fac9de83c99177a160ebb8d42fad075"},{"url":"https://git.kernel.org/stable/c/09883bf257f4243ed5a1fd35078ec6f0d0f3696a"},{"url":"https://git.kernel.org/stable/c/761b45c661af48da6a065868d59ab1e1f64fd9b6"},{"url":"https://git.kernel.org/stable/c/607245c4dbb86d9a10dd8388da0fb82170a99b61"},{"url":"https://git.kernel.org/stable/c/6b419700e459fbf707ca1543b7c1b57a60fedb73"},{"url":"https://git.kernel.org/stable/c/88a8f56e6276f616baad4274c6b8e4683e26e520"},{"url":"https://git.kernel.org/stable/c/f08ffa3e1c8e36b6131f69c5eb23700c28cbd262"},{"url":"https://git.kernel.org/stable/c/6d52a4a0520a6696bdde51caa11f2d6821cd0c01"}],"tags":["cve.org"],"epss":0.0012,"epssPercentile":0.02114,"ingestedAt":"2026-09-08T15:33:26.991Z","slug":"CVE-2026-31416","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: account for netlink header size\n\nThis is a followup to an old bug fix: NLMSG_DONE needs to account\nfor the netlink header size, not just the attribute size.\n\nThis can result in a WARN splat + drop of the netlink message,\nbut other than this there are no ill effects.\n\n## Affected\n\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 4ec216410fac9de83c99177a160ebb8d42fad075`\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 09883bf257f4243ed5a1fd35078ec6f0d0f3696a`\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 761b45c661af48da6a065868d59ab1e1f64fd9b6`\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 607245c4dbb86d9a10dd8388da0fb82170a99b61`\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 6b419700e459fbf707ca1543b7c1b57a60fedb73`\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 88a8f56e6276f616baad4274c6b8e4683e26e520`\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < f08ffa3e1c8e36b6131f69c5eb23700c28cbd262`\n- `Linux >= 9dfa1dfe4d5e5e66a991321ab08afe69759d797a < 6d52a4a0520a6696bdde51caa11f2d6821cd0c01`\n- `Linux 3a758a2b78da2f49f7165678faf999e946a0c4b5`\n- `Linux 131172845aa2c804ffa9423455aee585061ea35e`\n- `Linux b1fef6b81871a396f3b8702077333e769673c87b`\n- `Linux add9183d993c12fb61ce0a674a424341d5be5b36`\n- `Linux >= 3.10.61 < 3.11`\n- `Linux >= 3.12.34 < 3.13`\n- `Linux >= 3.14.25 < 3.15`\n- `Linux >= 3.17.4 < 3.18`\n- `Linux 3.18`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}