CVE-2026-31414

Source
https://cve.org/CVERecord?id=CVE-2026-31414
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31414.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-31414
Downstream
Published
2026-04-13T13:21:02.592Z
Modified
2026-05-22T03:54:34.389499537Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: nf_conntrack_expect: use expect->helper
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfconntrackexpect: use expect->helper

Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to the master conntrack is unsafe.

Use exp->master->helper in ctnetlink path if userspace does not provide an explicit helper when creating an expectation to retain the existing behaviour. The ctnetlink expectation path holds the reference on the master conntrack and nfconntrackexpect lock and the nfnetlink glue path refers to the master ct that is attached to the skb.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31414.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ea781f197d6a835cbb93a0bf88ee1696296ed8aa
Fixed
847cb7fe26c5ce5dce0d1a41fac1ea488b7f1781
Fixed
e7ccaa0a62a8ff2be5d521299ce79390c318d306
Fixed
4bd1b3d839172724b33d8d02c5a4ff6a1c775417
Fixed
b53294bff19e56ada2f230ceb8b1ffde61cc3817
Fixed
3dfd3f7712b5a800f2ba632179e9b738076a51f0
Fixed
f01794106042ee27e54af6fdf5b319a2fe3df94d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31414.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.30
Fixed
6.1.168
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.134
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.81
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.22
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31414.json"