VDB
CVE-2026-31418
CVE-2026-31418
PUBLISHED
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in mtype_del mtype_del() counts empty slots below n->pos in k, but it only drops the bucket when both n->pos and k are zero. This misses buckets whose live entries have all been removed while n->pos still points past deleted slots. Treat a bucket as empty when all positions below n->pos are unused and release it directly instead of shrinking it further.
EPSS 0.02% · 3.5th percentile
Risk Scores
EPSS Score
0.02%
3.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | *, 6.1.168, 6.6.134 |
| linux | linux_kernel | 5.6, 5.6, 5.6 |
Timeline
- Apr 13, 2026 CVE Published
- Apr 13, 2026 Security Advisory
- Apr 18, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
References
- https://git.kernel.org/stable/c/ad92ee87462f9a3061361d392e9dbfe2e5c1c9fb url
- https://git.kernel.org/stable/c/6cea34d7ec6829b62f521a37a287f670144a2233 url
- https://git.kernel.org/stable/c/b7eef00f08b92b0b9efe8ae0df6d0005e6199323 url
- https://git.kernel.org/stable/c/68ca0eea0af02bed36c5e2c13e9fa1647c31a7d4 url
- https://git.kernel.org/stable/c/ceacaa76f221a6577aba945bb8873c2e640aeba4 url
- https://git.kernel.org/stable/c/9862ef9ab0a116c6dca98842aab7de13a252ae02 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-31418 advisory