{"id":"CVE-2026-31420","title":"bridge: mrp: reject zero test interval to avoid OOM panic","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: mrp: reject zero test interval to avoid OOM panic\n\nbr_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied\ninterval value from netlink without v…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 610073ffb77ffd2b5eca182d2ac264de4834a175","Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < ec8850be9b2b3beac1c7967d95f169dd2785979d","Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 1ec86b4b9e28170a2565cf36f0e6e2b96b55134d","Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 2120bd8546cd6a63c558d135773aa8f41c8259fc","Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 630a15a31c2034b5b697f4aabc769b9d80d82446","Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < e8ec80430bfa520e7352155d6ac632e527cba7aa","Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < c9bc352f716d1bebfe43354bce539ec2d0223b30","Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < fa6e24963342de4370e3a3c9af41e38277b74cf3","Linux 5.8"],"published":"2026-04-13","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:16.075Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31420","references":[{"url":"https://git.kernel.org/stable/c/610073ffb77ffd2b5eca182d2ac264de4834a175"},{"url":"https://git.kernel.org/stable/c/ec8850be9b2b3beac1c7967d95f169dd2785979d"},{"url":"https://git.kernel.org/stable/c/1ec86b4b9e28170a2565cf36f0e6e2b96b55134d"},{"url":"https://git.kernel.org/stable/c/2120bd8546cd6a63c558d135773aa8f41c8259fc"},{"url":"https://git.kernel.org/stable/c/630a15a31c2034b5b697f4aabc769b9d80d82446"},{"url":"https://git.kernel.org/stable/c/e8ec80430bfa520e7352155d6ac632e527cba7aa"},{"url":"https://git.kernel.org/stable/c/c9bc352f716d1bebfe43354bce539ec2d0223b30"},{"url":"https://git.kernel.org/stable/c/fa6e24963342de4370e3a3c9af41e38277b74cf3"}],"tags":["cve.org"],"epss":0.00091,"epssPercentile":0.0056,"ingestedAt":"2026-09-14T15:23:07.459Z","slug":"CVE-2026-31420","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbridge: mrp: reject zero test interval to avoid OOM panic\n\nbr_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied\ninterval value from netlink without validation. When interval is 0,\nusecs_to_jiffies(0) yields 0, causing the delayed work\n(br_mrp_test_work_expired / br_mrp_in_test_work_expired) to reschedule\nitself with zero delay. This creates a tight loop on system_percpu_wq\nthat allocates and transmits MRP test frames at maximum rate, exhausting\nall system memory and causing a kernel panic via OOM deadlock.\n\nThe same zero-interval issue applies to br_mrp_start_in_test_parse()\nfor interconnect test frames.\n\nUse NLA_POLICY_MIN(NLA_U32, 1) in the nla_policy tables for both\nIFLA_BRIDGE_MRP_START_TEST_INTERVAL and\nIFLA_BRIDGE_MRP_START_IN_TEST_INTERVAL, so zero is rejected at the\nnetlink attribute parsing layer before the value ever reaches the\nworkqueue scheduling code. This is consistent with how other bridge\nsubsystems (br_fdb, br_mst) enforce range constraints on netlink\nattributes.\n\n## Affected\n\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 610073ffb77ffd2b5eca182d2ac264de4834a175`\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < ec8850be9b2b3beac1c7967d95f169dd2785979d`\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 1ec86b4b9e28170a2565cf36f0e6e2b96b55134d`\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 2120bd8546cd6a63c558d135773aa8f41c8259fc`\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 630a15a31c2034b5b697f4aabc769b9d80d82446`\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < e8ec80430bfa520e7352155d6ac632e527cba7aa`\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < c9bc352f716d1bebfe43354bce539ec2d0223b30`\n- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < fa6e24963342de4370e3a3c9af41e38277b74cf3`\n- `Linux 5.8`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}