9.1

CVE-2026-31682

bridge: br_nd_send: linearize skb before parsing ND options

In the Linux kernel, the following vulnerability has been resolved:

bridge: br_nd_send: linearize skb before parsing ND options

br_nd_send() parses neighbour discovery options from ns->opt[] and
assumes that these options are in the linear part of request.

Its callers only guarantee that the ICMPv6 header and target address
are available, so the option area can still be non-linear. Parsing
ns->opt[] in that case can access data past the linear buffer.

Linearize request before option parsing and derive ns from the linear
network header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.15 < 5.10.253
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.203
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.168
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.134
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.81
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.22
Linux ≫ Linux Kernel Version >= 6.19 < 6.19.12
Linux ≫ Linux Kernel Version 7.0 Update rc1
Linux ≫ Linux Kernel Version 7.0 Update rc2
Linux ≫ Linux Kernel Version 7.0 Update rc3
Linux ≫ Linux Kernel Version 7.0 Update rc4
Linux ≫ Linux Kernel Version 7.0 Update rc5
Linux ≫ Linux Kernel Version 7.0 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.385
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c68433fd291c9e88c00292095172c62d1997d662
Patch
https://git.kernel.org/stable/c/4f397b950c916e9a1f8a4fce04ea0110206cad47
Patch
https://git.kernel.org/stable/c/bd91ec85aa4c77d645bd2739fc56784157a88ca2
Patch
https://git.kernel.org/stable/c/658261898130da620fc3d0fbb0523efb3366cb55
Patch
https://git.kernel.org/stable/c/2ba4caba423ed94d63006eb1d2227b0332ab7fcd
Patch
https://git.kernel.org/stable/c/9c55e41c73af5c4511070933b1bd25248521270c
Patch
https://git.kernel.org/stable/c/3a30f6469b058574f49efde61cd6f5d79e576053
Patch
https://git.kernel.org/stable/c/a01aee7cafc575bb82f5529e8734e7052f9b16ea
Patch
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
https://cert-portal.siemens.com/productcert/html/ssa-019113.html