CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()

Published Apr 23, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ipv4: nexthop: allocate skb dynamically in rtmgetnexthop()

When querying a nexthop object via RTMGETNEXTHOP, the kernel currently allocates a fixed-size skb using NLMSGGOODSIZE. While sufficient for single nexthops and small Equal-Cost Multi-Path groups, this fixed allocation fails for large nexthop groups like 512 nexthops.

This results in the following warning splat:

WARNING: net/ipv4/nexthop.c:3395 at rtmgetnexthop+0x176/0x1c0, CPU#20: rep/4608 [...] RIP: 0010:rtmgetnexthop (net/ipv4/nexthop.c:3395) [...] Call Trace: <TASK> rtnetlinkrcvmsg (net/core/rtnetlink.c:6989) netlinkrcvskb (net/netlink/afnetlink.c:2550) netlinkunicast (net/netlink/afnetlink.c:1319 net/netlink/afnetlink.c:1344) netlinksendmsg (net/netlink/afnetlink.c:1894) syssendmsg (net/socket.c:721 net/socket.c:736 net/socket.c:2585) syssendmsg (net/socket.c:2641) syssendmsg (net/socket.c:2671) dosyscall64 (arch/x86/entry/syscall64.c:63 arch/x86/entry/syscall64.c:94) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:130) </TASK>

Fix this by allocating the size dynamically using nhnlmsgsize() and using nlmsgnew(), this is consistent with nexthopnotify() behavior. In addition, adjust nhnlmsgsizegrp() so it calculates the size needed based on flags passed. While at it, also add the size of NHAFDB for nexthop group size calculation as it was missing too.

This cannot be reproduced via iproute2 as the group size is currently limited and the command fails as follows:

addattrl ERROR: message exceeded bound of 1048

Affected Software

11 affected components
Linux Linux kernel
Linux Linux kernel>=5.3<6.12.83
Linux Linux kernel>=6.13<6.18.24
Linux Linux kernel>=6.19<6.19.14
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7

Event History

Apr 23, 2026
CVE Published
via MITRE·11:12 AM
Data Sourced
via MITRE·11:12 AM
Description
Data Sourced
via NVD·12:17 PM
RemedyDescriptionSeverityAffected Software
Apr 24, 2026
Data Sourced
via Microsoft·08:05 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-31531?

CVE-2026-31531 is classified as a medium severity vulnerability.

2

How do I fix CVE-2026-31531?

To mitigate CVE-2026-31531, update the Linux kernel to the latest version that includes the fix.

3

What impact does CVE-2026-31531 have on system security?

CVE-2026-31531 may allow attackers to exploit memory allocation issues, potentially leading to denial of service.

4

Which versions of the Linux kernel are affected by CVE-2026-31531?

CVE-2026-31531 affects multiple versions of the Linux kernel prior to the patch being applied.

5

What is the nature of the vulnerability in CVE-2026-31531?

CVE-2026-31531 involves dynamic memory allocation issues in the handling of nexthop objects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203