← All Advisories

CVE-2026-98031

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98031

Key Details

CVECVE-2026-98031
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

nexthop: Initialize extack in remove_nh_grp_entry()

remove_nh_grp_entry() prints the extack message when a listener fails

to replace the reduced nexthop group. However, extack is not

initialized and listeners are not required to set a message when

returning an error. Neither netdevsim nor mlxsw do so when an

allocation fails, resulting in the dereference of an uninitialized

stack pointer.

Fix by zero-initializing extack, as was done in commit 6347c5314cee

("nexthop: initialize extack in nh_res_bucket_migrate()"). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98031
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98031