Answer in brief
CVE-2026-31428 records a Medium severity (CVSS 5.5) vulnerability in netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-31428 records a Medium severity (CVSS 5.5) vulnerability in netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=df6fb868d6118686805c2fa566e213a8f31c8e4f <7f3e5d72455936f42709116fabeca3bb216cda62 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <21d8efda029948d3666b0db5afcc0d36c0984aae || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <fc961dd7272b5e4a462999635e44a4770d7f2482 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <a8365d1064ded323797c5e28e91070c52f44b76c || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <a2f6ff3444b663d6cfa63eadd61327a18592885a || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <c9f6c51d36482805ac3ffadb9663fe775a13e926 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <7eff72968161fb8ddb26113344de3b92fb7d7ef5 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <52025ebaa29f4eb4ed8bf92ce83a68f24ab7fdf7 | 7f3e5d72455936f42709116fabeca3bb216cda62, 21d8efda029948d3666b0db5afcc0d36c0984aae, fc961dd7272b5e4a462999635e44a4770d7f2482, a8365d1064ded323797c5e28e91070c52f44b76c, a2f6ff3444b663d6cfa63eadd61327a18592885a, c9f6c51d36482805ac3ffadb9663fe775a13e926, 7eff72968161fb8ddb26113344de3b92fb7d7ef5, 52025ebaa29f4eb4ed8bf92ce83a68f24ab7fdf7 |
| Linux/Linuxgeneric | 2.6.24 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
Published upstream
Apr 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD __build_packet_message() manually constructs the NFULA_PAYLOAD netlink attribute using skb_put() and skb_copy_bits(), bypassing the standard nla_reserve()/nla_put() helpers. While nla_total_size(data_len) bytes are allocated (including NLA alignment padding), only data_len bytes of actual packet data are copied. The trailing nla_padlen(data_len) bytes (1-3 when data_len is not 4-byte aligned) are never initialized, leaking stale heap contents to userspace via the NFLOG netlink socket. Replace the manual attribute construction with nla_reserve(), which handles the tailroom check, header setup, and padding zeroing via __nla_reserve(). The subsequent skb_copy_bits() fills in the payload data on top of the properly initialized attribute.
Quoted source text, attributed separately from HOL analysis.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=df6fb868d6118686805c2fa566e213a8f31c8e4f <7f3e5d72455936f42709116fabeca3bb216cda62 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <21d8efda029948d3666b0db5afcc0d36c0984aae || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <fc961dd7272b5e4a462999635e44a4770d7f2482 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <a8365d1064ded323797c5e28e91070c52f44b76c || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <a2f6ff3444b663d6cfa63eadd61327a18592885a || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <c9f6c51d36482805ac3ffadb9663fe775a13e926 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <7eff72968161fb8ddb26113344de3b92fb7d7ef5 || >=df6fb868d6118686805c2fa566e213a8f31c8e4f <52025ebaa29f4eb4ed8bf92ce83a68f24ab7fdf7 | 7f3e5d72455936f42709116fabeca3bb216cda62, 21d8efda029948d3666b0db5afcc0d36c0984aae, fc961dd7272b5e4a462999635e44a4770d7f2482, a8365d1064ded323797c5e28e91070c52f44b76c, a2f6ff3444b663d6cfa63eadd61327a18592885a, c9f6c51d36482805ac3ffadb9663fe775a13e926, 7eff72968161fb8ddb26113344de3b92fb7d7ef5, 52025ebaa29f4eb4ed8bf92ce83a68f24ab7fdf7 |
| Linux/Linuxgeneric | 2.6.24 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
Published upstream
Apr 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD __build_packet_message() manually constructs the NFULA_PAYLOAD netlink attribute using skb_put() and skb_copy_bits(), bypassing the standard nla_reserve()/nla_put() helpers. While nla_total_size(data_len) bytes are allocated (including NLA alignment padding), only data_len bytes of actual packet data are copied. The trailing nla_padlen(data_len) bytes (1-3 when data_len is not 4-byte aligned) are never initialized, leaking stale heap contents to userspace via the NFLOG netlink socket. Replace the manual attribute construction with nla_reserve(), which handles the tailroom check, header setup, and padding zeroing via __nla_reserve(). The subsequent skb_copy_bits() fills in the payload data on top of the properly initialized attribute.
Quoted source text, attributed separately from HOL analysis.