CVE-2026-31427Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp process_sdp() declares union nf_inet_addr rtp_addr on the stack and passes it to the nf_nat_sip sdp_session hook after walking the SDP media descriptions. However rtp_addr is only initialized inside the media loop when a recognized media type with a non-zero port is found. If the SDP body contains no m= lines, only inactive media sections (m=audio 0 ...) or only unrecognized media types, rtp_addr is never assigned. Despite that, the function still calls hooks->sdp_session() with &rtp_addr, causing nf_nat_sdp_session() to format the stale stack value as an IP address and rewrite the SDP session owner and connection lines with it. With CONFIG_INIT_STACK_ALL_ZERO (default on most distributions) this results in the session-level o= and c= addresses being rewritten to 0.0.0.0 for inactive SDP sessions. Without stack auto-init the rewritten address is whatever happened to be on the stack. Fix this by pre-initializing rtp_addr from the session-level connection address (caddr) when available, and tracking via a have_rtp_addr flag whether any valid address was established. Skip the sdp_session hook entirely when no valid address exists.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-13: 1Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-27: 104-1304-27
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-131
Patch1
2026-04-271
Disclosure1
Full discourse2 posts
  • James.zhu@zhulizhong
    Disclosure

    CVE-2026-31427: Linux Kernel Use-After-Free Vulnerability. The bug is confined to SIP sessions handled by the connection-tracking helper and NAT SDP hooks. It requires SIP traffic traversing a host with nf_conntrack_sip (and relevant NAT) loaded. The integrity of signaling is compromised; remote attackers who can pass SDP through the helper can influence the rewritten addresses. The scope should be reviewed against whether IPv4/IPv6 SIP transit applies (network vs. strictly local control plane). #CVE-2026-31427 #SIP

    Post summary

    The tweet discloses a new Linux kernel use‑after‑free vulnerability (CVE-2026-31427) that impacts SIP sessions via the connection-tracking helper and NAT SDP hooks, providing concrete technical details but no evidence of exploitation or remediation.

    0000063
    167 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31427 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp process_sdp() decl… https://www.cve.org/CVERecord?id=CVE-2026-31427

    Post summary

    The post announces that CVE-2026-31427, an uninitialized variable issue in nf_conntrack_sip, has been patched in the Linux kernel, providing a fix reference but no exploit or active attack data.

    0000065
    57.1K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more