CVE-2026-72419
Received
Received - Intake
Memory Corruption in Linux Kernel Netfilter NAT
Vulnerability report for CVE-2026-72419, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-15
Last updated on: 2026-08-15
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
We ran into below KASAN splat, which is mostly uninteresting, beside
for having nf_nat_register_fn() in the call chain as a cause for the
offending access:
==================================================================
BUG: KASAN: slab-out-of-bounds in nf_nat_register_fn+0x5f9/0x640
Read of size 8 at addr ffff890031e54c20 by task iptables/9510
CPU: 0 UID: 0 PID: 9510 Comm: iptables Not tainted 6.18.18-grsec-full-20260320181326 #1 PREEMPT(voluntary)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
[β¦] dump_stack_lvl+0xee/0x160 ffff88004117eeb8
[β¦] print_report+0x6e/0x640 ffff88004117eee0
[β¦] ? __phys_addr+0x8e/0x140 ffff88004117eef0
[β¦] ? kasan_addr_to_slab+0x51/0xe0 ffff88004117ef08
[β¦] ? complete_report_info+0xec/0x1c0 ffff88004117ef20
[β¦] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef48
[β¦] kasan_report+0xbc/0x140 ffff88004117ef50
[β¦] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef90
[β¦] nf_nat_register_fn+0x5f9/0x640 ffff88004117eff8
[β¦] ? nf_nat_icmp_reply_translation+0x6e0/0x6e0 ffff88004117f070
[β¦] nf_tables_register_hook.part.0+0xa0/0x220 ffff88004117f080
[β¦] nf_tables_addchain.constprop.0+0x1054/0x1fc0 ffff88004117f0b8
[β¦] ? nft_chain_lookup.part.0+0x4ce/0xac0 ffff88004117f130
[β¦] ? nf_tables_abort+0x3d80/0x3d80 ffff88004117f190
[β¦] ? nf_tables_dumpreset_obj+0x100/0x100 ffff88004117f1c8
[β¦] ? nft_table_lookup.part.0+0x255/0x300 ffff88004117f310
[β¦] ? nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f358
[β¦] nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f360
[β¦] ? nf_tables_addchain.constprop.0+0x1fc0/0x1fc0 ffff88004117f458
[β¦] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f488
[β¦] ? lock_acquire+0x16f/0x320 ffff88004117f490
[β¦] ? find_held_lock+0x3b/0xe0 ffff88004117f4b0
[β¦] ? __nla_parse+0x45/0x80 ffff88004117f500
[β¦] nfnetlink_rcv_batch+0xbca/0x19a0 ffff88004117f550
[β¦] ? nfnetlink_net_exit_batch+0x120/0x120 ffff88004117f618
[β¦] ? __sanitizer_cov_trace_switch+0x63/0xe0 ffff88004117f720
[β¦] ? gr_acl_handle_mmap+0x1c4/0x320 ffff88004117f7c0
[β¦] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f7e8
[β¦] ? gr_is_capable+0x6f/0xe0 ffff88004117f830
[β¦] ? __nla_parse+0x45/0x80 ffff88004117f860
[β¦] ? skb_pull+0x103/0x1a0 ffff88004117f880
[β¦] nfnetlink_rcv+0x3db/0x4a0 ffff88004117f8b0
[β¦] ? nfnetlink_rcv_batch+0x19a0/0x19a0 ffff88004117f8d8
[β¦] ? netlink_lookup+0xe2/0x240 ffff88004117f900
[β¦] netlink_unicast+0x74b/0xb00 ffff88004117f930
[β¦] ? netlink_attachskb+0xb20/0xb20 ffff88004117f980
[β¦] ? __check_object_size+0x3e/0xaa0 ffff88004117f998
[β¦] ? security_netlink_send+0x51/0x160 ffff88004117f9c8
[β¦] netlink_sendmsg+0xa03/0x1200 ffff88004117f9f8
[β¦] ? netlink_unicast+0xb00/0xb00 ffff88004117fa70
[β¦] ? netlink_unicast+0xb00/0xb00 ffff88004117fac8
[β¦] ? ____sys_sendmsg+0xe2a/0x1040 ffff88004117faf8
[β¦] ____sys_sendmsg+0xe2a/0x1040 ffff88004117fb00
[β¦] ? kernel_recvmsg+0x300/0x300 ffff88004117fb60
[β¦] ? reacquire_held_locks+0xe9/0x260 ffff88004117fbc8
[β¦] ___sys_sendmsg+0x138/0x200 ffff88004117fbf8
[β¦] ? do_recvmmsg+0x7e0/0x7e0 ffff88004117fc30
[β¦] ? lockdep_hardirqs_on_prepare+0x101/0x1e0 ffff88004117fc50
[β¦] ? lock_acquire+0x16f/0x320 ffff88004117fd20
[β¦] ? lock_acquire+0x16f/0x320 ffff88004117fd58
[β¦] ? find_held_lock+0x3b/0xe0 ffff88004117fd70
[β¦] __sys_sendmsg+0x17a/0x260 ffff88004117fdc8
[β¦] ? __sys_sendmsg_sock+0x80/0x80 ffff88004117fdf0
[β¦] ? syscall_trace_enter+0x15e/0x2c0 ffff88004117fe98
[β¦] do_syscall_64+0x7d/0x400 ffff88004117fec8
[β¦] entry_SYSCALL_64_safe_stack+0x4a/0x60 ffff88004117fef8
</TASK>
==================================================================
The out-of-bounds report, though, is a red herring as it is f
---truncated---
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux_kernel | linux_kernel | 6.18.18 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |