CVE-2026-98322: netfilter: nft_nat: fully initialise new_addr in netmap setup
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftnat: fully initialise newaddr in netmap setup
nftnatsetupnetmap() builds the mapped address in an on-stack union nfinetaddr. For an IPv4 mapping it writes only the 4-byte .ip member and the loop runs a single 32-bit iteration, but it then copies the whole 16-byte union into range->minaddr and range->maxaddr, so the upper 12 bytes reach nfnatsetupinfo() uninitialised.
KMSAN reports an uninit-value in nfnatsetupinfo() reached from nftnateval(). The IPv6 path fills all 16 bytes and is not affected.
Zero-initialise newaddr.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch netfilter: nft_nat: fully initialise new_addr in netmap setup
Event History
Frequently Asked Questions
Which traffic and address-family configurations are affected?
Only the IPv4 netmap path in nft_nat_setup_netmap() is affected. The IPv6 path initializes all 16 bytes of the address union and is not affected.
What condition is required to reach the vulnerable code?
The vulnerable path is reached when nft_nat_eval() processes an IPv4 netmap setup. The description does not establish whether this is present in default firewall rules or whether an unprivileged attacker can create the required rules.
What is the immediate mitigation if an update cannot be applied?
Avoid IPv4 netmap NAT configurations that invoke nft_nat_setup_netmap(). IPv6 netmap configurations are not affected by this specific uninitialized-address condition.