PT-2026-32340 · Linux+2 · Linux Kernel+2

CVE-2026-31414

·

Published

2026-03-26

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the netfilter component within the nf conntrack expect function. Using nfct help() without holding a reference to the master conntrack is unsafe. To maintain existing behavior, the ctnetlink path should use exp->master->helper when userspace does not provide an explicit helper during expectation creation. The ctnetlink expectation path maintains the reference on the master conntrack and the nf conntrack expect lock, while the nfnetlink glue path refers to the master ct attached to the skb.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-82706
BDU:2026-12268
CVE-2026-31414
ECHO-2B8D-3B31-1285
OESA-2026-2869
OESA-2026-2871
OESA-2026-3157
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2722-1
SUSE-SU-2026:2799-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8631-1
USN-8631-2
USN-8631-3
USN-8631-4
USN-8633-1
USN-8633-2
USN-8634-1
USN-8635-1
USN-8636-1
USN-8636-2
USN-8645-1
USN-8661-1
USN-8661-2
USN-8661-3
USN-8661-4
USN-8662-1
USN-8662-2
USN-8665-1
USN-8666-1
USN-8666-2
USN-8666-3
USN-8667-1
USN-8669-1
USN-8715-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu