« Volver al listado

CVE-2026-72251

Estado: RecibidaCrítica (9.8)—

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_nat_sip: reload possible stale data pointer

quoting sashiko: ------------------------------------------------------------------------ [..] noticed a potential memory bug and header corruption involving the SIP NAT helper.

If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the old data buffer is freed. However, nf_nat_sip() fails to update *dptr to point to the new buffer.

It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP packet, which would overwrite the sequence number with a checksum update. ------------------------------------------------------------------------

Leer descripción completaMostrar menos

nf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen. But clones are possible, so rebuild dptr.

Disable nf_nat_mangle_udp_packet() branch for TCP streams. It doesn't look like this can ever happen, else we should have received bug reports about this, so just check the conntrack is UDP and drop otherwise.

The calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages, so I don't think this is ever expected to be true for a TCP stream.

Detalles técnicos trazas, registros y código del informe original
 In net/netfilter/nf_nat_sip.c:nf_nat_sip():
	if (skb_ensure_writable(skb, skb->len)) {
		nf_ct_helper_log(skb, ct, "cannot mangle packet");
		return NF_DROP;
	}
	uh = (void *)skb->data + protoff;
	uh->dest = ct_sip_info->forced_dport;
	if (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,
				      0, 0, NULL, 0)) {

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota en kernel Linux (AV:N/AC:L/PR:N/UI:N) en netfilter SIP NAT que permite corrupción de memoria y datos de paquetes (header corruption, stale pointer) tras realocación de skb. Impacto: manipulación de datos de red y potencial DoS por corrupción de flujo.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72251",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "bded21a4bf9bf86a79148be735723a97ca9a7532",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "dc11f26685aa850f237226f0f463647aea58ab7c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "e38143c9b477f2968024c47c647dd4456a40aff1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "57e4e29644ec054d7021d296407e7ddd844afea2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "2bcf2c5052fb5e73e255140ab43f056aef409c27",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7266507d89991fa1e989283e4e032c6d9357fe26",
              "lessThan": "77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/netfilter/nf_nat_sip.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/netfilter/nf_nat_sip.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:52.393",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2bcf2c5052fb5e73e255140ab43f056aef409c27",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/57e4e29644ec054d7021d296407e7ddd844afea2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bded21a4bf9bf86a79148be735723a97ca9a7532",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dc11f26685aa850f237226f0f463647aea58ab7c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e38143c9b477f2968024c47c647dd4456a40aff1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat_sip: reload possible stale data pointer\n\nquoting sashiko:\n ------------------------------------------------------------------------\n [..] noticed a potential memory bug and header corruption involving the\n SIP NAT helper.\n\n In net/netfilter/nf_nat_sip.c:nf_nat_sip():\n\tif (skb_ensure_writable(skb, skb->len)) {\n\t\tnf_ct_helper_log(skb, ct, \"cannot mangle packet\");\n\t\treturn NF_DROP;\n\t}\n\tuh = (void *)skb->data + protoff;\n\tuh->dest = ct_sip_info->forced_dport;\n\tif (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,\n\t\t\t\t      0, 0, NULL, 0)) {\n\n If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the\n old data buffer is freed. However, nf_nat_sip() fails to update *dptr to\n point to the new buffer.\n\n It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP\n packet, which would overwrite the sequence number with a checksum update.\n ------------------------------------------------------------------------\n\nnf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen.\nBut clones are possible, so rebuild dptr.\n\nDisable nf_nat_mangle_udp_packet() branch for TCP streams.\nIt doesn't look like this can ever happen, else we should have received\nbug reports about this, so just check the conntrack is UDP and drop\notherwise.\n\nThe calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages,\nso I don't think this is ever expected to be true for a TCP stream."
    }
  ],
  "lastModified": "2026-08-17T06:18:27.173",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}