0.0
NA
CVE-2026-100070
netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP string is shorter or longer than the internal IP, coff will still point to the offset relative to the pre-mangled packet. If the packet shrinks, coff could overshoot the correct position, potentially causing the next ct_sip_parse_header_uri() call to silently skip bytes and miss subsequent Contact headers. Could this lead to a failure to NAT those subsequent headers and leak internal network details?

INFO

Published Date :

Sept. 25, 2026, 2:17 p.m.

Last Modified :

Sept. 30, 2026, 2:10 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-100070 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Update the Linux kernel to resolve packet handling issues in netfilter's SIP NAT module.
  • Apply the latest Linux kernel updates.
  • Verify the netfilter SIP NAT module is correctly configured.
  • Test packet handling after applying the update.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-100070 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-100070 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-100070 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-100070 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 25, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP string is shorter or longer than the internal IP, coff will still point to the offset relative to the pre-mangled packet. If the packet shrinks, coff could overshoot the correct position, potentially causing the next ct_sip_parse_header_uri() call to silently skip bytes and miss subsequent Contact headers. Could this lead to a failure to NAT those subsequent headers and leak internal network details?
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/100xxx/CVE-2026-100070.json">CVE-2026-100070</a>
    Added Reference https://git.kernel.org/stable/c/0f4d30e2e49f343fc28ba1e259fd22969b940c46
    Added Reference https://git.kernel.org/stable/c/16aecbe3036f6097c26b51b12e4c1cf207769690
    Added Reference https://git.kernel.org/stable/c/2703f5ea8d85bc729f433ac09ee902084c947122
    Added Reference https://git.kernel.org/stable/c/668cc1c30caedc63070b10d17d5514748988a140
    Added Reference https://git.kernel.org/stable/c/6828aca3d82717c2fda92af81c0dda642bc2b465
    Added Reference https://git.kernel.org/stable/c/810da5a63549531da78348b0a4545042d84e01e2
    Added Reference https://git.kernel.org/stable/c/c408d416618ebb8a95e3097a13f3b793ea9272ee
    Added Reference https://git.kernel.org/stable/c/e70d48fcf8382581162608a4a322919bfd22aef3
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.