ipv4 routing

  1. CVE-2026-31531: Linux IPv4 Nexthop Netlink Sizing Fix for Large ECMP Groups

    The Linux kernel has disclosed CVE-2026-31531, a networking bug in the IPv4 nexthop path that can trigger a kernel warning when users query very large nexthop groups through RTM_GETNEXTHOP. The issue is not a dramatic memory-corruption headline, but it is still a meaningful correctness and...
  2. Linux Kernel CVE-2024-36008 IPv4 Routing NULL Pointer Bug Fixed

    A subtle NULL‑pointer bug in the Linux kernel’s IPv4 routing code — tracked as CVE‑2024‑36008 — was patched in mid‑2024 after syzbot triggered a NULL dereference in fib_validate_source() that can crash a system processing IPv4 packets; the issue is real, reproducible in some configurations, and...