CVE-2026-31682: bridge: br_nd_send: linearize skb before parsing ND options
Published Apr 25, 2026
·Updated
bridge: brndsend: linearize skb before parsing ND options
Affected Software
15 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.130.1-3
Linux Linux kernel>=4.15<5.10.253
Linux Linux kernel>=5.11<5.15.203
Linux Linux kernel>=5.16<6.1.168
Linux Linux kernel>=6.2<6.6.134
Linux Linux kernel>=6.7<6.12.81
Linux Linux kernel>=6.13<6.18.22
Linux Linux kernel>=6.19<6.19.12
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Event History
Apr 25, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverity
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityAffected Software
Apr 26, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:09 AM
Affected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-31682?
CVE-2026-31682 has a medium severity rating due to potential data corruption in the neighbor discovery process.
2
How do I fix CVE-2026-31682?
To fix CVE-2026-31682, you should update your Linux kernel to the latest stable version that contains the patch.
3
What causes CVE-2026-31682?
CVE-2026-31682 is caused by improper parsing of Neighbor Discovery options in the Linux kernel's networking subsystem.
4
Which software versions are affected by CVE-2026-31682?
CVE-2026-31682 affects specific versions of the Linux kernel, particularly those prior to the patch release.
5
Is CVE-2026-31682 remotely exploitable?
CVE-2026-31682 has the potential for remote exploitation if an attacker can manipulate network packets.