{"id":"CVE-2026-31428","title":"netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD\n\n__build_packet_message() manually constructs the NFULA_PAYLOAD netlink\nattribute using skb_pu…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 7f3e5d72455936f42709116fabeca3bb216cda62","Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 21d8efda029948d3666b0db5afcc0d36c0984aae","Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < fc961dd7272b5e4a462999635e44a4770d7f2482","Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < a8365d1064ded323797c5e28e91070c52f44b76c","Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < a2f6ff3444b663d6cfa63eadd61327a18592885a","Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < c9f6c51d36482805ac3ffadb9663fe775a13e926","Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 7eff72968161fb8ddb26113344de3b92fb7d7ef5","Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 52025ebaa29f4eb4ed8bf92ce83a68f24ab7fdf7","Linux 2.6.24"],"published":"2026-04-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:47:04.591Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31428","references":[{"url":"https://git.kernel.org/stable/c/7f3e5d72455936f42709116fabeca3bb216cda62"},{"url":"https://git.kernel.org/stable/c/21d8efda029948d3666b0db5afcc0d36c0984aae"},{"url":"https://git.kernel.org/stable/c/fc961dd7272b5e4a462999635e44a4770d7f2482"},{"url":"https://git.kernel.org/stable/c/a8365d1064ded323797c5e28e91070c52f44b76c"},{"url":"https://git.kernel.org/stable/c/a2f6ff3444b663d6cfa63eadd61327a18592885a"},{"url":"https://git.kernel.org/stable/c/c9f6c51d36482805ac3ffadb9663fe775a13e926"},{"url":"https://git.kernel.org/stable/c/7eff72968161fb8ddb26113344de3b92fb7d7ef5"},{"url":"https://git.kernel.org/stable/c/52025ebaa29f4eb4ed8bf92ce83a68f24ab7fdf7"}],"tags":["cve.org"],"epss":0.00131,"epssPercentile":0.03053,"ingestedAt":"2026-09-08T15:33:26.990Z","slug":"CVE-2026-31428","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD\n\n__build_packet_message() manually constructs the NFULA_PAYLOAD netlink\nattribute using skb_put() and skb_copy_bits(), bypassing the standard\nnla_reserve()/nla_put() helpers. While nla_total_size(data_len) bytes\nare allocated (including NLA alignment padding), only data_len bytes\nof actual packet data are copied. The trailing nla_padlen(data_len)\nbytes (1-3 when data_len is not 4-byte aligned) are never initialized,\nleaking stale heap contents to userspace via the NFLOG netlink socket.\n\nReplace the manual attribute construction with nla_reserve(), which\nhandles the tailroom check, header setup, and padding zeroing via\n__nla_reserve(). The subsequent skb_copy_bits() fills in the payload\ndata on top of the properly initialized attribute.\n\n## Affected\n\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 7f3e5d72455936f42709116fabeca3bb216cda62`\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 21d8efda029948d3666b0db5afcc0d36c0984aae`\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < fc961dd7272b5e4a462999635e44a4770d7f2482`\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < a8365d1064ded323797c5e28e91070c52f44b76c`\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < a2f6ff3444b663d6cfa63eadd61327a18592885a`\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < c9f6c51d36482805ac3ffadb9663fe775a13e926`\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 7eff72968161fb8ddb26113344de3b92fb7d7ef5`\n- `Linux >= df6fb868d6118686805c2fa566e213a8f31c8e4f < 52025ebaa29f4eb4ed8bf92ce83a68f24ab7fdf7`\n- `Linux 2.6.24`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}