CVE-2026-72251
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_nat_sip: reload possible stale data pointer
quoting sashiko: ------------------------------------------------------------------------ [..] noticed a potential memory bug and header corruption involving the SIP NAT helper.
If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the old data buffer is freed. However, nf_nat_sip() fails to update *dptr to point to the new buffer.
It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP packet, which would overwrite the sequence number with a checksum update. ------------------------------------------------------------------------
Leer descripción completaMostrar menos
nf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen. But clones are possible, so rebuild dptr.
Disable nf_nat_mangle_udp_packet() branch for TCP streams. It doesn't look like this can ever happen, else we should have received bug reports about this, so just check the conntrack is UDP and drop otherwise.
The calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages, so I don't think this is ever expected to be true for a TCP stream.
Detalles técnicos trazas, registros y código del informe original
In net/netfilter/nf_nat_sip.c:nf_nat_sip():
if (skb_ensure_writable(skb, skb->len)) {
nf_ct_helper_log(skb, ct, "cannot mangle packet");
return NF_DROP;
}
uh = (void *)skb->data + protoff;
uh->dest = ct_sip_info->forced_dport;
if (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,
0, 0, NULL, 0)) {CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.71%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1565.002Transmitted Data Manipulationimpact75 % - Impacto secundario
T1499.004Application or System Exploitationimpact70 %
Vulnerabilidad remota en kernel Linux (AV:N/AC:L/PR:N/UI:N) en netfilter SIP NAT que permite corrupción de memoria y datos de paquetes (header corruption, stale pointer) tras realocación de skb. Impacto: manipulación de datos de red y potencial DoS por corrupción de flujo.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7
- https://git.kernel.org/stable/c/2bcf2c5052fb5e73e255140ab43f056aef409c27
- https://git.kernel.org/stable/c/57e4e29644ec054d7021d296407e7ddd844afea2
- https://git.kernel.org/stable/c/77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68
- https://git.kernel.org/stable/c/bded21a4bf9bf86a79148be735723a97ca9a7532
- https://git.kernel.org/stable/c/dc11f26685aa850f237226f0f463647aea58ab7c
- https://git.kernel.org/stable/c/e38143c9b477f2968024c47c647dd4456a40aff1
- https://git.kernel.org/stable/c/eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72251",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "bded21a4bf9bf86a79148be735723a97ca9a7532",
"versionType": "git"
},
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "dc11f26685aa850f237226f0f463647aea58ab7c",
"versionType": "git"
},
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "e38143c9b477f2968024c47c647dd4456a40aff1",
"versionType": "git"
},
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "57e4e29644ec054d7021d296407e7ddd844afea2",
"versionType": "git"
},
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17",
"versionType": "git"
},
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "2bcf2c5052fb5e73e255140ab43f056aef409c27",
"versionType": "git"
},
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7",
"versionType": "git"
},
{
"status": "affected",
"version": "7266507d89991fa1e989283e4e032c6d9357fe26",
"lessThan": "77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68",
"versionType": "git"
}
],
"programFiles": [
"net/netfilter/nf_nat_sip.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/netfilter/nf_nat_sip.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:52.393",
"references": [
{
"url": "https://git.kernel.org/stable/c/0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2bcf2c5052fb5e73e255140ab43f056aef409c27",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/57e4e29644ec054d7021d296407e7ddd844afea2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bded21a4bf9bf86a79148be735723a97ca9a7532",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dc11f26685aa850f237226f0f463647aea58ab7c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e38143c9b477f2968024c47c647dd4456a40aff1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat_sip: reload possible stale data pointer\n\nquoting sashiko:\n ------------------------------------------------------------------------\n [..] noticed a potential memory bug and header corruption involving the\n SIP NAT helper.\n\n In net/netfilter/nf_nat_sip.c:nf_nat_sip():\n\tif (skb_ensure_writable(skb, skb->len)) {\n\t\tnf_ct_helper_log(skb, ct, \"cannot mangle packet\");\n\t\treturn NF_DROP;\n\t}\n\tuh = (void *)skb->data + protoff;\n\tuh->dest = ct_sip_info->forced_dport;\n\tif (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,\n\t\t\t\t 0, 0, NULL, 0)) {\n\n If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the\n old data buffer is freed. However, nf_nat_sip() fails to update *dptr to\n point to the new buffer.\n\n It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP\n packet, which would overwrite the sequence number with a checksum update.\n ------------------------------------------------------------------------\n\nnf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen.\nBut clones are possible, so rebuild dptr.\n\nDisable nf_nat_mangle_udp_packet() branch for TCP streams.\nIt doesn't look like this can ever happen, else we should have received\nbug reports about this, so just check the conntrack is UDP and drop\notherwise.\n\nThe calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages,\nso I don't think this is ever expected to be true for a TCP stream."
}
],
"lastModified": "2026-08-17T06:18:27.173",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}