CVE-2026-31752

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: validate ND option lengths br_nd_send() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*

History

14 Jul 2026, 13:18

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-019113.html -
  • () https://cert-portal.siemens.com/productcert/html/ssa-082556.html -

07 May 2026, 19:08

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/259466f76f5a2148aff11134e68f4b4c6d52725b - () https://git.kernel.org/stable/c/259466f76f5a2148aff11134e68f4b4c6d52725b - Patch
References () https://git.kernel.org/stable/c/82a42eceec7c6bdb0e0da94c0542a173b7ea57f2 - () https://git.kernel.org/stable/c/82a42eceec7c6bdb0e0da94c0542a173b7ea57f2 - Patch
References () https://git.kernel.org/stable/c/837392a38445729c22e03d3abcf33f07763efd85 - () https://git.kernel.org/stable/c/837392a38445729c22e03d3abcf33f07763efd85 - Patch
References () https://git.kernel.org/stable/c/850837965af15707fd3142c1cf3c5bfaf022299b - () https://git.kernel.org/stable/c/850837965af15707fd3142c1cf3c5bfaf022299b - Patch
References () https://git.kernel.org/stable/c/c49b9256bbacb6a135654aebd12e4c0e87166b7c - () https://git.kernel.org/stable/c/c49b9256bbacb6a135654aebd12e4c0e87166b7c - Patch
References () https://git.kernel.org/stable/c/e0bfd6d4dc77ab345b6c65eef0cfe9b2f69085aa - () https://git.kernel.org/stable/c/e0bfd6d4dc77ab345b6c65eef0cfe9b2f69085aa - Patch
References () https://git.kernel.org/stable/c/e71303a9190496136e240c4f2872b7b0b16027a7 - () https://git.kernel.org/stable/c/e71303a9190496136e240c4f2872b7b0b16027a7 - Patch
References () https://git.kernel.org/stable/c/ee02d8991fd7bd86ed6ebd0deb4aab53feb0e43a - () https://git.kernel.org/stable/c/ee02d8991fd7bd86ed6ebd0deb4aab53feb0e43a - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

01 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-01 15:16

Updated : 2026-07-14 13:18


NVD link : CVE-2026-31752

Mitre link : CVE-2026-31752

CVE.ORG link : CVE-2026-31752


JSON object : View

Products Affected

linux

  • linux_kernel