UNKNOWN NVD
CVE-2026-80664
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nat: reject unsupported target families xt_nat SNAT and DNAT target handlers
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_nat: reject unsupported target families
xt_nat SNAT and DNAT target handlers assume IP-family conntrack state
is present and can dereference a NULL pointer when instantiated from an
unsupported family through nft_compat. A bridge-family compat rule can
therefore trigger a NULL-dereference in nf_nat_setup_info().
Reject non-IP families in xt_nat_checkentry() so unsupported targets
cannot be installed. Keep NFPROTO_INET allowed for valid inet NAT
compat users and leave the runtime fast path unchanged.
[ The crash was fixed via
9dbba7e694ec ("netfilter: nft_compat: ebtables emulation must reject non-bridge targets"),
so this patch is no longer critical.
Nevertheless, NAT is only relevant for ipv4/ipv6, so this extra
family check is a good idea in any case. ]
References
- https://git.kernel.org/stable/c/0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82
- https://git.kernel.org/stable/c/49abe564391411057a26a9a943c8e17867c3b9b4
- https://git.kernel.org/stable/c/4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777
- https://git.kernel.org/stable/c/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd
- https://git.kernel.org/stable/c/679ced28a9dc2f6dc679eb05027d779693e60902
This unknown severity vulnerability was published on 2026-08-28 via NVD.
vulnfeed aggregates 11380 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.