Incorrect calculation in Linux kernel - CVE-2026-100070
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose internal network details.
The vulnerability exists due to an incorrect calculation of the Contact-header parsing offset in nf_nat_sip when processing a SIP packet whose NAT address translation changes its length. A remote attacker can send a SIP packet containing subsequent Contact headers to disclose internal network details.
Exploitation requires NAT address translation to shorten the packet.
Affected software
How to mitigate CVE-2026-100070
External References
- https://git.kernel.org/stable/c/0f4d30e2e49f343fc28ba1e259fd22969b940c46
- https://git.kernel.org/stable/c/16aecbe3036f6097c26b51b12e4c1cf207769690
- https://git.kernel.org/stable/c/2703f5ea8d85bc729f433ac09ee902084c947122
- https://git.kernel.org/stable/c/668cc1c30caedc63070b10d17d5514748988a140
- https://git.kernel.org/stable/c/6828aca3d82717c2fda92af81c0dda642bc2b465
- https://git.kernel.org/stable/c/810da5a63549531da78348b0a4545042d84e01e2
- https://git.kernel.org/stable/c/c408d416618ebb8a95e3097a13f3b793ea9272ee
- https://git.kernel.org/stable/c/e70d48fcf8382581162608a4a322919bfd22aef3