CVE-2026-98322: netfilter: nft_nat: fully initialise new_addr in netmap setup

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nftnat: fully initialise newaddr in netmap setup

nftnatsetupnetmap() builds the mapped address in an on-stack union nfinetaddr. For an IPv4 mapping it writes only the 4-byte .ip member and the loop runs a single 32-bit iteration, but it then copies the whole 16-byte union into range->minaddr and range->maxaddr, so the upper 12 bytes reach nfnatsetupinfo() uninitialised.

KMSAN reports an uninit-value in nfnatsetupinfo() reached from nftnateval(). The IPv6 path fills all 16 bytes and is not affected.

Zero-initialise newaddr.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch netfilter: nft_nat: fully initialise new_addr in netmap setup

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:29 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which traffic and address-family configurations are affected?

Only the IPv4 netmap path in nft_nat_setup_netmap() is affected. The IPv6 path initializes all 16 bytes of the address union and is not affected.

2

What condition is required to reach the vulnerable code?

The vulnerable path is reached when nft_nat_eval() processes an IPv4 netmap setup. The description does not establish whether this is present in default firewall rules or whether an unprivileged attacker can create the required rules.

3

What is the immediate mitigation if an update cannot be applied?

Avoid IPv4 netmap NAT configurations that invoke nft_nat_setup_netmap(). IPv6 netmap configurations are not affected by this specific uninitialized-address condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203