---
id: CVE-2026-31681
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: xt_multiport: validate range encoding in checkentry

  ports_match_v1() treats any non-zero pflags entry as the start of a
  port range and unconditionally consu…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: xt_multiport: validate range encoding in checkentry

  ports_match_v1() treats any non-zero pflags entry as the start of a
  port range and unconditionally consu…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.17, < 6.6.136'
  - 'linux_kernel >= 6.7, < 6.12.83'
  - 'linux_kernel >= 6.13, < 6.18.24'
  - 'linux_kernel >= 6.19, < 6.19.14'
  - linux_kernel = 7.0
patched:
  - linux_kernel 6.19.14
published: '2026-04-25'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T09:17:59.380'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31681'
references:
  - url: 'https://git.kernel.org/stable/c/1e4baa853f1cc4227e04f52d6860524707cfb294'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/36bf0d98e180a7c384c8d8a59b0d2d4b80e5eb16'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8368ce8eb01f0b91111d814703696e780d0ef12f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8c5bf8f5b478f569191c4a7982de7cd5f5f73c1a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aec14808271f2bf2b656de6ff12dfe73c5fd3b67'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b67d638cbee9975c765feb45c126e96ed11ec802'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c9749f6232c845e31c21d4cc72200211df15d8a2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ff64c5bfef12461df8450e0f50bb693b5269c720'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
  - cve.org
epss: 0.0017
epssPercentile: 0.0565
ingestedAt: '2026-09-08T09:30:09.793Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_multiport: validate range encoding in checkentry

ports_match_v1() treats any non-zero pflags entry as the start of a
port range and unconditionally consumes the next ports[] element as
the range end.

The checkentry path currently validates protocol, flags and count, but
it does not validate the range encoding itself. As a result, malformed
rules can mark the last slot as a range start or place two range starts
back to back, leaving ports_match_v1() to step past the last valid
ports[] element while interpreting the rule.

Reject malformed multiport v1 rules in checkentry by validating that
each range start has a following element and that the following element
is not itself marked as another range start.

## Affected

- `linux_kernel >= 2.6.17, < 6.6.136`
- `linux_kernel >= 6.7, < 6.12.83`
- `linux_kernel >= 6.13, < 6.18.24`
- `linux_kernel >= 6.19, < 6.19.14`
- `linux_kernel = 7.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.14`
