Impact
In the Linux kernel’s netfilter nf_nat subsystem, an error during the insertion of NAT hooks can cause the hooks to never be released, resulting in a memory leak. The leak arises because the code path that unregisters the hooks is not executed when nf_hook_entries_insert_raw fails. This flaw does not directly allow code execution but can lead to resource exhaustion or denial‑of‑service conditions if the leak accumulates over time.
Affected Systems
The vulnerability affects all Linux kernel implementations that include the nf_nat module and lack the patch applied in recent commits. No specific version range is listed, so any kernel build prior to the fix is potentially impacted.
Risk and Exploitability
While the CVSS score is not provided and EPSS is unavailable, the lack of a known exploit in CISA’s KEV catalog indicates no publicly demonstrated attacks. The risk is primarily moderate; an attacker with the ability to trigger the kernel hook insertion failure—likely a local or privileged user—could cause memory pressure and degrade system availability. The exploit path is inferred to require local kernel code execution, as the fault occurs within internal NF hook registration logic.
OpenCVE Enrichment