KernelScan.io

CRITICAL Introduced in 2.6.20

netfilter SIP NAT OOB

CVE-2026-53002

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_content_len() while at it. BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270 Write of size 1 at addr [..] vsnprintf+0xea5/0x1270 sprintf+0xb1/0xe0 mangle_content_len+0x1ac/0x280 nf_nat_sdp_session+0x1cc/0x240 process_sdp+0x8f8/0xb80 process_invite_request+0x108/0x2b0 process_sip_msg+0x5da/0xf50 sip_help_tcp+0x45e/0x780 nf_confirm+0x34d/0x990 [..]

02

Engine v0.3.0

Risk summary

A remote attacker can send a crafted SIP packet through a Linux system running the nf_nat_sip conntrack helper, triggering a stack out-of-bounds write in mangle_content_len(). This can cause kernel memory corruption leading to a kernel panic or system crash. No authentication or user interaction is required since the vulnerable code is reached via network packet processing.

Affectednet/netfilter/nf_nat_sip.c (netfilter SIP NAT helper)

Vulnerability analysis

The root cause is that mangle_content_len() in nf_nat_sip.c declared a stack buffer of only sizeof("65536") = 6 bytes, but used sprintf() (which has no bounds checking) to write a content-length value that can be up to 10 digits (up to 4294967295 for a u32). When a SIP packet with a sufficiently large SDP content-length is processed through NAT, sprintf() writes beyond the 6-byte stack buffer, causing a stack out-of-bounds write as confirmed by the KASAN report. Additional sprintf() calls in sip_sprintf_addr() and sip_sprintf_addr_port() also lacked bounds checking. The fix replaces all sprintf() calls with scnprintf() (which respects buffer size limits) and increases the mangle_content_len() buffer to sizeof("4294967295") = 11 bytes to accommodate the maximum possible value. The attack surface is network-reachable: any system with the nf_nat_sip kernel module loaded (typically on SIP-aware NAT gateways/firewalls) that processes SIP INVITE packets with crafted SDP content is vulnerable. No privileges are required from the attacker's perspective — the vulnerability is triggered by inbound network traffic.

03

BranchIntroducedFixed inPatch commit
5.102.6.205.10.2582f793ba78470
5.152.6.205.15.2096bbf829b4c1b
6.12.6.206.1.175ab64e61c9323
6.62.6.206.6.1411c9fb8aeed06
6.122.6.206.12.91a8e0a32a23d3
7.02.6.207.0.10c08ff52e4494
mainline2.6.207.16e7066bdb481
6.182.6.206.18.338e3be0d12615