Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-72251

netfilter: nf_nat_sip: reload possible stale data pointer
Back to all
CVE

CVE-2026-72251

netfilter: nf_nat_sip: reload possible stale data pointer

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnatsip: reload possible stale data pointer

quoting sashiko:

 ------------------------------------------------------------------------

 [..] noticed a potential memory bug and header corruption involving the

 SIP NAT helper.

 In net/netfilter/nfnatsip.c:nfnatsip():

if (skbensurewritable(skb, skb->len)) {

nfcthelper_log(skb, ct, "cannot mangle packet");

return NF_DROP;

}

uh = (void *)skb->data + protoff;

uh->dest = ctsipinfo->forced_dport;

if (!nfnatmangleudppacket(skb, ct, ctinfo, protoff,

      0, 0, NULL, 0)) {

 If a cloned or fragmented SKB is reallocated by skbensurewritable(), the

 old data buffer is freed. However, nfnatsip() fails to update *dptr to

 point to the new buffer.

 It also appears to use nfnatmangleudppacket() on what could be a TCP

 packet, which would overwrite the sequence number with a checksum update.

 ------------------------------------------------------------------------

nfconntracksip linerizes skbs, hence no fragmented skb can be seen.

But clones are possible, so rebuild dptr.

Disable nfnatmangleudppacket() branch for TCP streams.

It doesn't look like this can ever happen, else we should have received

bug reports about this, so just check the conntrack is UDP and drop

otherwise.

The calling conntracksip set ->forceddport for SIPHDRVIA_UDP messages,

so I don't think this is ever expected to be true for a TCP stream.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7, https://git.kernel.org/stable/c/2bcf2c5052fb5e73e255140ab43f056aef409c27, https://git.kernel.org/stable/c/57e4e29644ec054d7021d296407e7ddd844afea2, https://git.kernel.org/stable/c/77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68, https://git.kernel.org/stable/c/bded21a4bf9bf86a79148be735723a97ca9a7532, https://git.kernel.org/stable/c/dc11f26685aa850f237226f0f463647aea58ab7c, https://git.kernel.org/stable/c/e38143c9b477f2968024c47c647dd4456a40aff1, https://git.kernel.org/stable/c/eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72251.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72251, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00714%
EPSS Percentile
0.51004%
Introduced Version
7266507d89991fa1e989283e4e032c6d9357fe26,3.9.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68,5.10.261,5.15.212,6.1.178,6.6.145,6.12.97,6.18.40,7.1.5,6.1.180-1,5.10.262-1,6.12.100-1,0:5.15.213-150.251.amzn2,0:1.0-0.amzn2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading