{"id":"CVE-2026-31496","title":"netfilter: nf_conntrack_expect: skip expectations in other netns via proc","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_expect: skip expectations in other netns via proc\n\nSkip expectations that do not reside in this netns.\n\nSimilar to e77e6ff502ea (\"netfilter: con…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 2028405ea6987b4448784e439413202cfe19f43f","Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 168145c87444619e3e649322bbe7719ecd00d411","Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < dcfcd95b3ae7683e8ae55c92284b3430ce614bc7","Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 9ca8c7452493d915f9bbf2f39331e6c583d07a23","Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 3265ad619987cb551edaf797ed056d80ac450225","Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 3db5647984de03d9cae0dcddb509b058351f0ee4","Linux 2.6.28"],"published":"2026-04-22","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:47:27.857Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31496","references":[{"url":"https://git.kernel.org/stable/c/2028405ea6987b4448784e439413202cfe19f43f"},{"url":"https://git.kernel.org/stable/c/168145c87444619e3e649322bbe7719ecd00d411"},{"url":"https://git.kernel.org/stable/c/dcfcd95b3ae7683e8ae55c92284b3430ce614bc7"},{"url":"https://git.kernel.org/stable/c/9ca8c7452493d915f9bbf2f39331e6c583d07a23"},{"url":"https://git.kernel.org/stable/c/3265ad619987cb551edaf797ed056d80ac450225"},{"url":"https://git.kernel.org/stable/c/3db5647984de03d9cae0dcddb509b058351f0ee4"}],"tags":["cve.org"],"epss":0.00123,"epssPercentile":0.0234,"ingestedAt":"2026-09-08T15:33:26.990Z","slug":"CVE-2026-31496","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_expect: skip expectations in other netns via proc\n\nSkip expectations that do not reside in this netns.\n\nSimilar to e77e6ff502ea (\"netfilter: conntrack: do not dump other netns's\nconntrack entries via proc\").\n\n## Affected\n\n- `Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 2028405ea6987b4448784e439413202cfe19f43f`\n- `Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 168145c87444619e3e649322bbe7719ecd00d411`\n- `Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < dcfcd95b3ae7683e8ae55c92284b3430ce614bc7`\n- `Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 9ca8c7452493d915f9bbf2f39331e6c583d07a23`\n- `Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 3265ad619987cb551edaf797ed056d80ac450225`\n- `Linux >= 9b03f38d0487f3908696242286d934c9b38f9d2a < 3db5647984de03d9cae0dcddb509b058351f0ee4`\n- `Linux 2.6.28`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}