CVE-2026-31738
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/2026
Last modified:
07/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
vxlan: validate ND option lengths in vxlan_na_create<br />
<br />
vxlan_na_create() walks ND options according to option-provided<br />
lengths. A malformed option can make the parser advance beyond the<br />
computed option span or use a too-short source LLADDR option payload.<br />
<br />
Validate option lengths against the remaining NS option area before<br />
advancing, and only read source LLADDR when the option is large enough<br />
for an Ethernet address.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.12.18 (including) | 3.13 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.13.10 (including) | 3.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.14.1 (including) | 5.10.253 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.203 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.168 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.134 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.81 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.22 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:3.14:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.14:rc8:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2029712fb2c87e9a8c75094906f2ee29bf08c500
- https://git.kernel.org/stable/c/602596c69a70e50d9ab8c6ae0290a01f88229dd7
- https://git.kernel.org/stable/c/901c1dd3bab2955d7e664f914c374c8c3ac2b958
- https://git.kernel.org/stable/c/afa9a05e6c4971bd5586f1b304e14d61fb3d9385
- https://git.kernel.org/stable/c/b69c4236255bd8de16cd876e58c6f0867d1d78b1
- https://git.kernel.org/stable/c/de20d2e3b9179d132f5f5b44e490d7c916c6321b
- https://git.kernel.org/stable/c/e476745917a1e288eb15e7ff49d286a86a4861d3
- https://git.kernel.org/stable/c/eddfce70a6f3107d1679b0c2fcbeb96b593bd679



