KernelScan.io

CRITICAL Introduced in 2.6.34

netfilter SipDelta Overflow

CVE-2026-74569

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() sip_help_tcp() stores the size change of each NAT-rewritten SIP message in s16 diff and accumulates it in s16 tdiff, but a single message can grow by more than S16_MAX while the packet stays under the 65535 enlarge_skb() limit: nf_nat_sip() rewrites every matching URI, and a long Contact list expands the message by tens of kilobytes. diff then wraps, and "datalen = datalen + diff - msglen" yields a huge unsigned datalen, so the next iteration's ct_sip_get_header() reads past the linearized skb tail. Widen diff, tdiff and the seq_adjust hook to s32. Both are bounded by the 65535 byte packet limit, and the seqadj core is already s32 (nf_ct_seqadj_set() takes s32), so no previously accepted input is rejected. BUG: KASAN: use-after-free in ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464) Read of size 1 at addr ffff888010800000 by task ksoftirqd/1/25 ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464) sip_help_tcp (net/netfilter/nf_conntrack_sip.c:1694) nf_confirm (net/netfilter/nf_conntrack_proto.c:183) nf_hook_slow (net/netfilter/core.c:619) ip6_output (net/ipv6/ip6_output.c:246) ip6_forward (net/ipv6/ip6_output.c:690) ipv6_rcv (net/ipv6/ip6_input.c:351) __netif_receive_skb_one_core (net/core/dev.c:6212) process_backlog (net/core/dev.c:6676) __napi_poll (net/core/dev.c:7735) net_rx_action (net/core/dev.c:7955) handle_softirqs (kernel/softirq.c:622) run_ksoftirqd (kernel/softirq.c:1076) ...

02

Engine v0.6.0

Risk summary

A network attacker can send a crafted SIP-over-TCP message through a firewall performing SIP NAT to trigger a signed 16-bit integer overflow in the connection tracking helper, causing an out-of-bounds read past the packet buffer. This can leak kernel memory or crash the kernel. Any device that forwards SIP traffic with conntrack NAT enabled is affected.

Affectednet/netfilter/nf_conntrack_sip.c (netfilter SIP conntrack helper)

Vulnerability analysis

The SIP connection tracking helper tracks how much each NAT-rewritten SIP message grows using a 16-bit signed integer, but a single message can expand by more than 32 KB when NAT rewrites many URIs in a long Contact list. The size delta wraps around, producing a corrupted length that causes the helper to read past the end of the linearized packet buffer on the next iteration. The fix widens the delta and related fields to 32-bit integers, which can hold the full 65535-byte packet size range without overflow. An attacker can trigger this by sending a crafted SIP-over-TCP message through a firewall that performs SIP NAT, needing no privileges beyond the ability to route traffic through the device.

03

BranchIntroducedFixed inPatch commit
5.152.6.345.15.2161b0843f9e9b9
6.12.6.346.1.18332d4abc8923b
6.62.6.346.6.15163eea41759fd
mainline2.6.347.2db3d0e0e5d4b
5.102.6.345.10.265ed1f9be6dc8e
7.12.6.347.1.8ef5e2c6555d2
6.122.6.346.12.103c97621a110e3
6.182.6.346.18.44f74554e67ccf