VDB

CVE-2026-31752

CVE-2026-31752 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: validate ND option lengths br_nd_send() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address.

EPSS 0.01% · 2.4th percentile

Risk Scores

EPSS Score
0.01%
2.4th percentile

Affected Products

VendorProductVersions
LinuxLinux*, 6.1.168, 6.6.134
linuxlinux_kernel4.15, 4.15, 4.15

Timeline

  • May 1, 2026 CVE Published
  • May 11, 2026 CVE Updated
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›