CVE-2026-98031

Source
https://cve.org/CVERecord?id=CVE-2026-98031
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98031.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98031
Downstream
Published
2026-09-25T10:23:47Z
Modified
2026-09-26T03:48:31Z
Summary
nexthop: Initialize extack in remove_nh_grp_entry()
Details

In the Linux kernel, the following vulnerability has been resolved:

nexthop: Initialize extack in remove_nh_grp_entry()

remove_nh_grp_entry() prints the extack message when a listener fails to replace the reduced nexthop group. However, extack is not initialized and listeners are not required to set a message when returning an error. Neither netdevsim nor mlxsw do so when an allocation fails, resulting in the dereference of an uninitialized stack pointer.

Fix by zero-initializing extack, as was done in commit 6347c5314cee ("nexthop: initialize extack in nh_res_bucket_migrate()").

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98031.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
833a1065eeb14437a9a0dfa9dad06ea09894e0b5
Fixed
030c878eaedf0449e2b5401a0a0146d0afcc645e
Fixed
d643cea4248668dc493c513aa7cbc6505eb1a4a9
Fixed
d80677ad7aa5bebfccfd58caa4852b65abe70561
Fixed
5bd9e4e7cdaa03879e9b73b12ab52cceb1edd55b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98031.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98031.json"