U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2026-31738 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: vxlan: validate ND option lengths in vxlan_na_create vxlan_na_create() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://git.kernel.org/stable/c/2029712fb2c87e9a8c75094906f2ee29bf08c500 kernel.org
https://git.kernel.org/stable/c/602596c69a70e50d9ab8c6ae0290a01f88229dd7 kernel.org
https://git.kernel.org/stable/c/901c1dd3bab2955d7e664f914c374c8c3ac2b958 kernel.org
https://git.kernel.org/stable/c/afa9a05e6c4971bd5586f1b304e14d61fb3d9385 kernel.org
https://git.kernel.org/stable/c/b69c4236255bd8de16cd876e58c6f0867d1d78b1 kernel.org
https://git.kernel.org/stable/c/de20d2e3b9179d132f5f5b44e490d7c916c6321b kernel.org
https://git.kernel.org/stable/c/e476745917a1e288eb15e7ff49d286a86a4861d3 kernel.org
https://git.kernel.org/stable/c/eddfce70a6f3107d1679b0c2fcbeb96b593bd679 kernel.org

Weakness Enumeration

CWE-ID CWE Name Source

Change History

1 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2026-31738
NVD Published Date:
05/01/2026
NVD Last Modified:
05/01/2026
Source:
kernel.org