Impact
The vulnerability arises when the nft_nat netmap setup code copies a 16‑byte union representing an IPv4 address into the NAT range structure after only initializing the lower 4 bytes. The upper 12 bytes remain uninitialized and are subsequently used by nf_nat_setup_info during NAT evaluation. This improper use of uninitialized kernel memory can corrupt kernel data structures, potentially leading to a kernel crash or unexpected behavior, which could allow an attacker to cause a denial of service or, less likely, trigger more serious memory corruption. The flaw is limited to the IPv4 path of nft_nat netmap; the IPv6 mapping correctly initializes all 16 bytes and is unaffected. The fix zero‑initializes the new_addr structure, eliminating the uninitialized data. Information about the CVSS score is not provided in the data, so the exact severity remains unknown. However the exploitability is non‑zero: an attacker who can send crafted network packets that trigger the netmap NAT path could activate the bug. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, indicating no known public exploits as of the latest data.
Affected Systems
All Linux kernel versions that compile the netfilter nft_nat netmap code prior to the patch are affected. The problem exists in the core kernel source, so any distribution kernel that has not applied the upstream commit restoring full initialisation is vulnerable.
Risk and Exploitability
The lack of an EPSS score and absence from the KEV catalog suggest a lower public exploitation probability, yet the nature of the bug – uninitialized kernel memory – is a serious defect. Attackers would need to craft specific network traffic that engages the nft_nat netmap subsystem, which is typically reachable from the local machine’s networking stack. Although the immediate impact is a failure of kernel stability, the potential for more serious consequences (e.g., privilege escalation) cannot be ruled out without further analysis.
OpenCVE Enrichment