Bug 2546362 (CVE-2026-98322) - CVE-2026-98322 kernel: netfilter: nft_nat: fully initialise new_addr in netmap setup
Summary: CVE-2026-98322 kernel: netfilter: nft_nat: fully initialise new_addr in netma...
Keywords:
Status: NEW
Alias: CVE-2026-98322
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 09:05 UTC by OSIDB Bzimport
Modified: 2026-10-10 06:54 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 09:05:56 UTC
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_nat: fully initialise new_addr in netmap setup

nft_nat_setup_netmap() builds the mapped address in an on-stack
union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip
member and the loop runs a single 32-bit iteration, but it then copies
the whole 16-byte union into range->min_addr and range->max_addr, so the
upper 12 bytes reach nf_nat_setup_info() uninitialised.

KMSAN reports an uninit-value in nf_nat_setup_info() reached from
nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected.

Zero-initialise new_addr.


Note You need to log in before you can comment on or make changes to this bug.