CRITICAL Introduced in 2.6.20
netfilter SIP NAT OOB
CVE-2026-53002
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_content_len() while at it. BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270 Write of size 1 at addr [..] vsnprintf+0xea5/0x1270 sprintf+0xb1/0xe0 mangle_content_len+0x1ac/0x280 nf_nat_sdp_session+0x1cc/0x240 process_sdp+0x8f8/0xb80 process_invite_request+0x108/0x2b0 process_sip_msg+0x5da/0xf50 sip_help_tcp+0x45e/0x780 nf_confirm+0x34d/0x990 [..]
02KernelScan AI Analysis
Risk summary
A remote attacker can send a crafted SIP packet through a Linux system running the nf_nat_sip conntrack helper, triggering a stack out-of-bounds write in mangle_content_len(). This can cause kernel memory corruption leading to a kernel panic or system crash. No authentication or user interaction is required since the vulnerable code is reached via network packet processing.
Vulnerability analysis
The root cause is that mangle_content_len() in nf_nat_sip.c declared a stack buffer of only sizeof("65536") = 6 bytes, but used sprintf() (which has no bounds checking) to write a content-length value that can be up to 10 digits (up to 4294967295 for a u32). When a SIP packet with a sufficiently large SDP content-length is processed through NAT, sprintf() writes beyond the 6-byte stack buffer, causing a stack out-of-bounds write as confirmed by the KASAN report. Additional sprintf() calls in sip_sprintf_addr() and sip_sprintf_addr_port() also lacked bounds checking. The fix replaces all sprintf() calls with scnprintf() (which respects buffer size limits) and increases the mangle_content_len() buffer to sizeof("4294967295") = 11 bytes to accommodate the maximum possible value. The attack surface is network-reachable: any system with the nf_nat_sip kernel module loaded (typically on SIP-aware NAT gateways/firewalls) that processes SIP INVITE packets with crafted SDP content is vulnerable. No privileges are required from the attacker's perspective — the vulnerability is triggered by inbound network traffic.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 2.6.20 | 5.10.258 | 2f793ba78470 |
| 5.15 | 2.6.20 | 5.15.209 | 6bbf829b4c1b |
| 6.1 | 2.6.20 | 6.1.175 | ab64e61c9323 |
| 6.6 | 2.6.20 | 6.6.141 | 1c9fb8aeed06 |
| 6.12 | 2.6.20 | 6.12.91 | a8e0a32a23d3 |
| 7.0 | 2.6.20 | 7.0.10 | c08ff52e4494 |
| mainline | 2.6.20 | 7.1 | 6e7066bdb481 |
| 6.18 | 2.6.20 | 6.18.33 | 8e3be0d12615 |