{"id":"CVE-2026-31418","title":"netfilter: ipset: drop logically empty buckets in mtype_del","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: drop logically empty buckets in mtype_del\n\nmtype_del() counts empty slots below n->pos in k, but it only drops the\nbucket when both n->pos and k are z…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < c098ff857e7ca923539164af5b3c2fe3e8f8afaf","Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 58f3a14826d4e6b0d5421f1a64be280b48601ea2","Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < ad92ee87462f9a3061361d392e9dbfe2e5c1c9fb","Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 6cea34d7ec6829b62f521a37a287f670144a2233","Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < b7eef00f08b92b0b9efe8ae0df6d0005e6199323","Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 68ca0eea0af02bed36c5e2c13e9fa1647c31a7d4","Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < ceacaa76f221a6577aba945bb8873c2e640aeba4","Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 9862ef9ab0a116c6dca98842aab7de13a252ae02","Linux 6c717726f341fd8f39a3ec2dcf5d98d9d28a2769","Linux d2997d64dfa65082236bca1efd596b6c935daf5e","Linux >= 5.4.24 < 5.5","Linux >= 5.5.8 < 5.6","Linux 5.6"],"published":"2026-04-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:46:55.323Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31418","references":[{"url":"https://git.kernel.org/stable/c/c098ff857e7ca923539164af5b3c2fe3e8f8afaf"},{"url":"https://git.kernel.org/stable/c/58f3a14826d4e6b0d5421f1a64be280b48601ea2"},{"url":"https://git.kernel.org/stable/c/ad92ee87462f9a3061361d392e9dbfe2e5c1c9fb"},{"url":"https://git.kernel.org/stable/c/6cea34d7ec6829b62f521a37a287f670144a2233"},{"url":"https://git.kernel.org/stable/c/b7eef00f08b92b0b9efe8ae0df6d0005e6199323"},{"url":"https://git.kernel.org/stable/c/68ca0eea0af02bed36c5e2c13e9fa1647c31a7d4"},{"url":"https://git.kernel.org/stable/c/ceacaa76f221a6577aba945bb8873c2e640aeba4"},{"url":"https://git.kernel.org/stable/c/9862ef9ab0a116c6dca98842aab7de13a252ae02"}],"tags":["cve.org"],"epss":0.0012,"epssPercentile":0.02081,"ingestedAt":"2026-09-08T15:33:26.991Z","slug":"CVE-2026-31418","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: drop logically empty buckets in mtype_del\n\nmtype_del() counts empty slots below n->pos in k, but it only drops the\nbucket when both n->pos and k are zero. This misses buckets whose live\nentries have all been removed while n->pos still points past deleted slots.\n\nTreat a bucket as empty when all positions below n->pos are unused and\nrelease it directly instead of shrinking it further.\n\n## Affected\n\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < c098ff857e7ca923539164af5b3c2fe3e8f8afaf`\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 58f3a14826d4e6b0d5421f1a64be280b48601ea2`\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < ad92ee87462f9a3061361d392e9dbfe2e5c1c9fb`\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 6cea34d7ec6829b62f521a37a287f670144a2233`\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < b7eef00f08b92b0b9efe8ae0df6d0005e6199323`\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 68ca0eea0af02bed36c5e2c13e9fa1647c31a7d4`\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < ceacaa76f221a6577aba945bb8873c2e640aeba4`\n- `Linux >= 8af1c6fbd9239877998c7f5a591cb2c88d41fb66 < 9862ef9ab0a116c6dca98842aab7de13a252ae02`\n- `Linux 6c717726f341fd8f39a3ec2dcf5d98d9d28a2769`\n- `Linux d2997d64dfa65082236bca1efd596b6c935daf5e`\n- `Linux >= 5.4.24 < 5.5`\n- `Linux >= 5.5.8 < 5.6`\n- `Linux 5.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}