{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80664","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.781Z","datePublished":"2026-08-28T06:49:07.478Z","dateUpdated":"2026-08-29T06:21:50.580Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-29T06:21:50.580Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_nat: reject unsupported target families\n\nxt_nat SNAT and DNAT target handlers assume IP-family conntrack state\nis present and can dereference a NULL pointer when instantiated from an\nunsupported family through nft_compat. A bridge-family compat rule can\ntherefore trigger a NULL-dereference in nf_nat_setup_info().\n\nReject non-IP families in xt_nat_checkentry() so unsupported targets\ncannot be installed. Keep NFPROTO_INET allowed for valid inet NAT\ncompat users and leave the runtime fast path unchanged.\n\n[ The crash was fixed via\n  9dbba7e694ec (\"netfilter: nft_compat: ebtables emulation must reject non-bridge targets\"),\n  so this patch is no longer critical.\n  Nevertheless, NAT is only relevant for ipv4/ipv6, so this extra\n  family check is a good idea in any case. ]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","baseScore":7.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires installing a bridge-family nft_compat SNAT/DNAT rule via NETLINK_NETFILTER (nftables netlink), a local syscall path; although matching bridge traffic can trigger evaluation, the vulnerable rule state cannot be created without local netfilter administration.\nAC:L - Once CAP_NET_ADMIN is held in the target network namespace, xt_request_find_target() deterministically resolves UNSPEC-family SNAT/DNAT rev 1/2 targets for bridge chains, and sending bridge traffic through the committed rule reliably reaches nf_nat_setup_info() with a NULL nf_conn from nf_ct_get().\nPR:L - All nfnetlink handlers are gated by netlink_net_capable(skb, CAP_NET_ADMIN), which checks capability in the socket network namespace user namespace; unprivileged local users routinely obtain CAP_NET_ADMIN via user and network namespaces (unshare -Urn), enabling installation of the malicious bridge compat rule.\nUI:N - No victim interaction is required beyond the attacker obtaining namespace-local CAP_NET_ADMIN, creating a bridge nftables chain with a compat SNAT/DNAT target, and delivering matching bridge traffic; no third-party actions such as mounting filesystems or opening files are needed.\nS:U - Impact is confined to the host kernel netfilter/NAT subsystem within the same security authority; this is not a VM escape, hypervisor boundary crossing, or IOMMU/DMA sandbox bypass, but standard in-kernel misbehavior from an invalid family/target pairing.\nC:L - The primary runtime failure is a NULL nf_conn dereference in nf_nat_setup_info(), and the surrounding nft_compat bridge/xtables semantic mismatch can leak limited kernel information via oops register dumps and crash logs readable by the local attacker who triggered the fault.\nI:H - Missing family validation lets IP-family NAT targets execute under bridge nft_compat semantics where nf_ct_get() yields NULL, constituting a type/family confusion that can corrupt netfilter verdict and NAT handling before faulting; mis-instantiated SNAT/DNAT targets should not run in bridge context at all.\nA:H - Passing bridge traffic through a bridge-family compat SNAT/DNAT rule causes nf_nat_setup_info() to dereference the NULL connection from nf_ct_get(), producing a kernel oops or panic; repeated matching traffic can retrigger the crash for sustained denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/xt_nat.c"],"versions":[{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"49abe564391411057a26a9a943c8e17867c3b9b4","status":"affected","versionType":"git"},{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82","status":"affected","versionType":"git"},{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777","status":"affected","versionType":"git"},{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"a842dab87cab29f2a5798a47b2dc5e6a449950bf","status":"affected","versionType":"git"},{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"e35c048d7511e9d4c2a537b8a231c49606e97c16","status":"affected","versionType":"git"},{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"679ced28a9dc2f6dc679eb05027d779693e60902","status":"affected","versionType":"git"},{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"ec88fa71c82072e9189983b05b499d3507550271","status":"affected","versionType":"git"},{"version":"c7232c9979cba684c50b64c513c4a83c9aa70563","lessThan":"5d1a2240935ea47e2673d0ea17fdb058e4dc91dd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/xt_nat.c"],"versions":[{"version":"3.7","status":"affected"},{"version":"0","lessThan":"3.7","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/49abe564391411057a26a9a943c8e17867c3b9b4"},{"url":"https://git.kernel.org/stable/c/0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82"},{"url":"https://git.kernel.org/stable/c/4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777"},{"url":"https://git.kernel.org/stable/c/a842dab87cab29f2a5798a47b2dc5e6a449950bf"},{"url":"https://git.kernel.org/stable/c/e35c048d7511e9d4c2a537b8a231c49606e97c16"},{"url":"https://git.kernel.org/stable/c/679ced28a9dc2f6dc679eb05027d779693e60902"},{"url":"https://git.kernel.org/stable/c/ec88fa71c82072e9189983b05b499d3507550271"},{"url":"https://git.kernel.org/stable/c/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd"}],"title":"netfilter: xt_nat: reject unsupported target families","x_generator":{"engine":"bippy-1.2.0"}}}}