Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_sip: validate skb_dst() before accessing it

tc ingress and openvswitch do not guarantee routing information to be
available. These subsystems use the conntrack helper infrastructure, and
the SIP helper relies on the skb_dst() to be present if
sip_external_media is set to 1 (which is disabled by default as a module
parameter).

This effectively disables the sip_external_media toggle for these
subsystems without resulting in a crash.
Published: 2026-08-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The nf_conntrack_sip helper in the Linux kernel assumes that the packet’s routing information, accessed via skb_dst(), is present when the sip_external_media module parameter is set to 1. However, subsystems such as traffic‑control ingress and Open vSwitch do not guarantee that routing data is available. Without a guard check, the helper preemptively disables the external media capability instead of correctly processing the packet. This results in a loss of functionality for SIP traffic that relies on external media support, effectively creating a denial of service to that feature without crashing the system.

Affected Systems

All Linux kernel releases that include the nf_conntrack_sip helper without the upstream validation patch are affected. The vendor is Linux and the product is the Linux kernel. Because no specific kernel version range is provided, every kernel that lacks the patch should be considered vulnerable. The issue manifests in configurations where sip_external_media is enabled for traffic that traverses subsystems that may not supply routing context, notably traffic‑control ingress and Open vSwitch.

Risk and Exploitability

The CVSS score of 7.5 categorizes the issue as high severity, but the EPSS <1% and absence from CISA’s KEV listing suggest that exploitation is unlikely to be widespread. An attacker could trigger the problem by sending SIP packets that activate the helper on a system using tc ingress or Open vSwitch where routing information is missing. Because the flaw only disables a functionality rather than crashing the kernel, the impact is limited to the loss of SIP external media support.

Generated by OpenCVE AI on August 17, 2026 at 17:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the nf_conntrack_sip skb_dst() validation patch
  • If SIP external media support is not required, set the kernel module parameter sip_external_media to 0 or unload the nf_conntrack_sip helper
  • Verify that traffic‑control ingress and Open vSwitch configurations do not enable nf_conntrack_sip when routing information may be missing

Generated by OpenCVE AI on August 17, 2026 at 17:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4745-1 linux-6.12 security update
History

Sun, 23 Aug 2026 13:15:00 +0000


Wed, 19 Aug 2026 00:15:00 +0000


Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: validate skb_dst() before accessing it tc ingress and openvswitch do not guarantee routing information to be available. These subsystems use the conntrack helper infrastructure, and the SIP helper relies on the skb_dst() to be present if sip_external_media is set to 1 (which is disabled by default as a module parameter). This effectively disables the sip_external_media toggle for these subsystems without resulting in a crash.
Title netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-23T12:47:08.038Z

Reserved: 2026-08-09T03:40:39.915Z

Link: CVE-2026-72253

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:52.760

Modified: 2026-08-23T13:16:42.497

Link: CVE-2026-72253

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72253 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T17:45:03Z

Weaknesses