CVE-2026-74569
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfconntracksip: widen NAT rewrite delta to s32 in siphelptcp()
siphelptcp() stores the size change of each NAT-rewritten SIP message
in s16 diff and accumulates it in s16 tdiff, but a single message can
grow by more than S16_MAX while the packet stays under the 65535
enlargeskb() limit: nfnat_sip() rewrites every matching URI, and a long
Contact list expands the message by tens of kilobytes. diff then wraps,
and "datalen = datalen + diff - msglen" yields a huge unsigned datalen,
so the next iteration's ctsipget_header() reads past the linearized skb
tail.
Widen diff, tdiff and the seq_adjust hook to s32. Both are bounded by the
65535 byte packet limit, and the seqadj core is already s32
(nfctseqadj_set() takes s32), so no previously accepted input is
rejected.
BUG: KASAN: use-after-free in ctsipgetheader (net/netfilter/nfconntrack_sip.c:464)
Read of size 1 at addr ffff888010800000 by task ksoftirqd/1/25
ctsipgetheader (net/netfilter/nfconntrack_sip.c:464)
siphelptcp (net/netfilter/nfconntracksip.c:1694)
nfconfirm (net/netfilter/nfconntrack_proto.c:183)
nfhookslow (net/netfilter/core.c:619)
ip6output (net/ipv6/ip6output.c:246)
ip6forward (net/ipv6/ip6output.c:690)
ipv6rcv (net/ipv6/ip6input.c:351)
_netifreceiveskbone_core (net/core/dev.c:6212)
process_backlog (net/core/dev.c:6676)
_napipoll (net/core/dev.c:7735)
netrxaction (net/core/dev.c:7955)
handle_softirqs (kernel/softirq.c:622)
run_ksoftirqd (kernel/softirq.c:1076)
...
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1b0843f9e9b9b0b9b4b70d143b67e58163c85b2c, https://git.kernel.org/stable/c/32d4abc8923b0d4046fd63ad6e4917872e44eb6d, https://git.kernel.org/stable/c/63eea41759fd682229c14e0a2205802b46d106f3, https://git.kernel.org/stable/c/c97621a110e386b2dd69e276eb699e1d3cec581d, https://git.kernel.org/stable/c/db3d0e0e5d4bc5ab4fe445b9f413d1b486508ca5, https://git.kernel.org/stable/c/ed1f9be6dc8e2e280b8725e44ccdc6e0cd38640d, https://git.kernel.org/stable/c/ef5e2c6555d2bb52dfe0e4053a8c6193f9d83b64, https://git.kernel.org/stable/c/f74554e67ccf04d1fa71069e8c9afa2717e40716, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74569.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74569, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git