Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_nat: fully initialise new_addr in netmap setup

nft_nat_setup_netmap() builds the mapped address in an on-stack
union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip
member and the loop runs a single 32-bit iteration, but it then copies
the whole 16-byte union into range->min_addr and range->max_addr, so the
upper 12 bytes reach nf_nat_setup_info() uninitialised.

KMSAN reports an uninit-value in nf_nat_setup_info() reached from
nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected.

Zero-initialise new_addr.
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

The vulnerability arises when the nft_nat netmap setup code copies a 16‑byte union representing an IPv4 address into the NAT range structure after only initializing the lower 4 bytes. The upper 12 bytes remain uninitialized and are subsequently used by nf_nat_setup_info during NAT evaluation. This improper use of uninitialized kernel memory can corrupt kernel data structures, potentially leading to a kernel crash or unexpected behavior, which could allow an attacker to cause a denial of service or, less likely, trigger more serious memory corruption. The flaw is limited to the IPv4 path of nft_nat netmap; the IPv6 mapping correctly initializes all 16 bytes and is unaffected. The fix zero‑initializes the new_addr structure, eliminating the uninitialized data. Information about the CVSS score is not provided in the data, so the exact severity remains unknown. However the exploitability is non‑zero: an attacker who can send crafted network packets that trigger the netmap NAT path could activate the bug. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, indicating no known public exploits as of the latest data.

Affected Systems

All Linux kernel versions that compile the netfilter nft_nat netmap code prior to the patch are affected. The problem exists in the core kernel source, so any distribution kernel that has not applied the upstream commit restoring full initialisation is vulnerable.

Risk and Exploitability

The lack of an EPSS score and absence from the KEV catalog suggest a lower public exploitation probability, yet the nature of the bug – uninitialized kernel memory – is a serious defect. Attackers would need to craft specific network traffic that engages the nft_nat netmap subsystem, which is typically reachable from the local machine’s networking stack. Although the immediate impact is a failure of kernel stability, the potential for more serious consequences (e.g., privilege escalation) cannot be ruled out without further analysis.

Generated by OpenCVE AI on October 6, 2026 at 14:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the commit restoring full initialization of new_addr in nft_nat netmap
  • If the nft_nat netmap feature is not required, disable it through kernel configuration or sysctl settings to avoid exercising the vulnerable code
  • After applying updates or disabling the feature, reboot the system to ensure the running kernel is the fixed version

Generated by OpenCVE AI on October 6, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-919

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_nat: fully initialise new_addr in netmap setup nft_nat_setup_netmap() builds the mapped address in an on-stack union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip member and the loop runs a single 32-bit iteration, but it then copies the whole 16-byte union into range->min_addr and range->max_addr, so the upper 12 bytes reach nf_nat_setup_info() uninitialised. KMSAN reports an uninit-value in nf_nat_setup_info() reached from nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected. Zero-initialise new_addr.
Title netfilter: nft_nat: fully initialise new_addr in netmap setup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:46:16.346Z

Reserved: 2026-09-25T10:25:14.340Z

Link: CVE-2026-98322

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:24.243

Modified: 2026-10-06T09:18:24.243

Link: CVE-2026-98322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T14:30:07Z

Weaknesses