Junglewise Threat Intelligence

CVE-2026-74569: Linux kernel netfilter use-after-free in SIP NAT rewrite

CVE-2026-74569 · Severity: critical · CVSS 9.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's SIP (Session Initiation Protocol) connection tracking module can cause the system to read memory beyond packet boundaries, potentially leading to system crashes or unauthorized information disclosure. This affects network devices and servers that use SIP filtering to manage VoIP traffic and NAT (Network Address Translation) operations.

Technical details

The vulnerability is a use-after-free condition in nf_conntrack_sip.c's sip_help_tcp() function, triggered by integer overflow in NAT rewrite delta calculation. The function stores NAT message size changes in a 16-bit signed integer (s16), but a single SIP message can grow beyond S16_MAX (32,767 bytes) when multiple URIs are rewritten, causing diff to wrap around. This overflow propagates to datalen calculation, resulting in an extremely large unsigned value that causes subsequent ct_sip_get_header() calls to read past the linearized socket buffer tail. The fix widens diff and tdiff from s16 to s32, matching the seqadj core's s32 handling. Attack requires network-level access to send specially crafted SIP packets with large contact lists through a NAT'd connection. No patch bypass or user interaction is required.

Affected products

  • Linux Linux kernel versions with vulnerable nf_conntrack_sip module

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched: Patch available in kernel commit resolving integer overflow in s16 diff to s32

Related threats