CVE-2026-100070
netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP string is shorter or longer than the internal IP, coff will still point to the offset relative to the pre-mangled packet. If the packet shrinks, coff could overshoot the correct position, potentially causing the next ct_sip_parse_header_uri() call to silently skip bytes and miss subsequent Contact headers. Could this lead to a failure to NAT those subsequent headers and leak internal network details?
INFO
Published Date :
Sept. 25, 2026, 2:17 p.m.
Last Modified :
Sept. 30, 2026, 2:10 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Apply the latest Linux kernel updates.
- Verify the netfilter SIP NAT module is correctly configured.
- Test packet handling after applying the update.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-100070.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-100070 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-100070
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-100070 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-100070 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sep. 25, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP string is shorter or longer than the internal IP, coff will still point to the offset relative to the pre-mangled packet. If the packet shrinks, coff could overshoot the correct position, potentially causing the next ct_sip_parse_header_uri() call to silently skip bytes and miss subsequent Contact headers. Could this lead to a failure to NAT those subsequent headers and leak internal network details? Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/100xxx/CVE-2026-100070.json">CVE-2026-100070</a> Added Reference https://git.kernel.org/stable/c/0f4d30e2e49f343fc28ba1e259fd22969b940c46 Added Reference https://git.kernel.org/stable/c/16aecbe3036f6097c26b51b12e4c1cf207769690 Added Reference https://git.kernel.org/stable/c/2703f5ea8d85bc729f433ac09ee902084c947122 Added Reference https://git.kernel.org/stable/c/668cc1c30caedc63070b10d17d5514748988a140 Added Reference https://git.kernel.org/stable/c/6828aca3d82717c2fda92af81c0dda642bc2b465 Added Reference https://git.kernel.org/stable/c/810da5a63549531da78348b0a4545042d84e01e2 Added Reference https://git.kernel.org/stable/c/c408d416618ebb8a95e3097a13f3b793ea9272ee Added Reference https://git.kernel.org/stable/c/e70d48fcf8382581162608a4a322919bfd22aef3