CVE-2026-31685: Linux Kernel
Critical severity, CVSS 9.4. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of the IPv6 source address. The existing guard only rejects an invalid MAC header when `par->fragoff != 0`. For packets with `par->fragoff == 0`, `eui64_mt6()` can still reach `eth_hdr(skb)` even when the MAC header is not valid. Fix this by removing the `par->fragoff != 0` condition so that packets with an invalid MAC header are rejected before accessing `eth_hdr(skb)`.
Affected products
- Linux Linux Kernel: from 2.6.12.1, before 6.6.136 (fixed in 6.6.136); from 6.7, before 6.12.83 (fixed in 6.12.83); from 6.13, before 6.18.24 (fixed in 6.18.24); from 6.19, before 6.19.14 (fixed in 6.19.14); version 2.6.12 only; version 7.0 only
Published 2026-04-25. Last modified 2026-06-17.