« Volver al listado

CVE-2026-98031

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nexthop: Initialize extack in remove_nh_grp_entry()

remove_nh_grp_entry() prints the extack message when a listener fails to replace the reduced nexthop group. However, extack is not initialized and listeners are not required to set a message when returning an error. Neither netdevsim nor mlxsw do so when an allocation fails, resulting in the dereference of an uninitialized stack pointer.

Fix by zero-initializing extack, as was done in commit 6347c5314cee ("nexthop: initialize extack in nh_res_bucket_migrate()").

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98031",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "833a1065eeb14437a9a0dfa9dad06ea09894e0b5",
              "lessThan": "35d9ec61466109ef0c2de87067338d929f629527",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "833a1065eeb14437a9a0dfa9dad06ea09894e0b5",
              "lessThan": "704319510af2179cf03955747d714ab291075c25",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "833a1065eeb14437a9a0dfa9dad06ea09894e0b5",
              "lessThan": "17acbcd4c5a6ca3dd3f9e52eb203c9175bde609a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "833a1065eeb14437a9a0dfa9dad06ea09894e0b5",
              "lessThan": "030c878eaedf0449e2b5401a0a0146d0afcc645e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "833a1065eeb14437a9a0dfa9dad06ea09894e0b5",
              "lessThan": "d643cea4248668dc493c513aa7cbc6505eb1a4a9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "833a1065eeb14437a9a0dfa9dad06ea09894e0b5",
              "lessThan": "d80677ad7aa5bebfccfd58caa4852b65abe70561",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "833a1065eeb14437a9a0dfa9dad06ea09894e0b5",
              "lessThan": "5bd9e4e7cdaa03879e9b73b12ab52cceb1edd55b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ipv4/nexthop.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv4/nexthop.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:31.787",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/030c878eaedf0449e2b5401a0a0146d0afcc645e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/17acbcd4c5a6ca3dd3f9e52eb203c9175bde609a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/35d9ec61466109ef0c2de87067338d929f629527",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5bd9e4e7cdaa03879e9b73b12ab52cceb1edd55b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/704319510af2179cf03955747d714ab291075c25",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d643cea4248668dc493c513aa7cbc6505eb1a4a9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d80677ad7aa5bebfccfd58caa4852b65abe70561",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: Initialize extack in remove_nh_grp_entry()\n\nremove_nh_grp_entry() prints the extack message when a listener fails\nto replace the reduced nexthop group. However, extack is not\ninitialized and listeners are not required to set a message when\nreturning an error. Neither netdevsim nor mlxsw do so when an\nallocation fails, resulting in the dereference of an uninitialized\nstack pointer.\n\nFix by zero-initializing extack, as was done in commit 6347c5314cee\n(\"nexthop: initialize extack in nh_res_bucket_migrate()\")."
    }
  ],
  "lastModified": "2026-10-03T11:18:26.073",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}