NULL pointer dereference in Linux kernel - CVE-2026-80664
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in xt_nat SNAT and DNAT target handlers when installing an unsupported-family compat rule through nft_compat. A local user can instantiate a bridge-family compat rule to cause a denial of service.
The issue is triggered in nf_nat_setup_info() because the handlers assume IP-family conntrack state is present.
Affected software
How to mitigate CVE-2026-80664
External References
- https://git.kernel.org/stable/c/0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82
- https://git.kernel.org/stable/c/49abe564391411057a26a9a943c8e17867c3b9b4
- https://git.kernel.org/stable/c/4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777
- https://git.kernel.org/stable/c/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd
- https://git.kernel.org/stable/c/679ced28a9dc2f6dc679eb05027d779693e60902
- https://git.kernel.org/stable/c/a842dab87cab29f2a5798a47b2dc5e6a449950bf
- https://git.kernel.org/stable/c/e35c048d7511e9d4c2a537b8a231c49606e97c16
- https://git.kernel.org/stable/c/ec88fa71c82072e9189983b05b499d3507550271