{"api_version":"1","generated_at":"2026-08-21T19:53:28+00:00","cve":"CVE-2026-72419","urls":{"html":"https://cve.report/CVE-2026-72419","api":"https://cve.report/api/cve/CVE-2026-72419.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72419","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72419"},"summary":{"title":"netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()\n\nWe ran into below KASAN splat, which is mostly uninteresting, beside\nfor having nf_nat_register_fn() in the call chain as a cause for the\noffending access:\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in nf_nat_register_fn+0x5f9/0x640\nRead of size 8 at addr ffff890031e54c20 by task iptables/9510\n\nCPU: 0 UID: 0 PID: 9510 Comm: iptables Not tainted 6.18.18-grsec-full-20260320181326 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <TASK>\n […] dump_stack_lvl+0xee/0x160 ffff88004117eeb8\n […] print_report+0x6e/0x640 ffff88004117eee0\n […] ? __phys_addr+0x8e/0x140 ffff88004117eef0\n […] ? kasan_addr_to_slab+0x51/0xe0 ffff88004117ef08\n […] ? complete_report_info+0xec/0x1c0 ffff88004117ef20\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef48\n […] kasan_report+0xbc/0x140 ffff88004117ef50\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef90\n […] nf_nat_register_fn+0x5f9/0x640 ffff88004117eff8\n […] ? nf_nat_icmp_reply_translation+0x6e0/0x6e0 ffff88004117f070\n […] nf_tables_register_hook.part.0+0xa0/0x220 ffff88004117f080\n […] nf_tables_addchain.constprop.0+0x1054/0x1fc0 ffff88004117f0b8\n […] ? nft_chain_lookup.part.0+0x4ce/0xac0 ffff88004117f130\n […] ? nf_tables_abort+0x3d80/0x3d80 ffff88004117f190\n […] ? nf_tables_dumpreset_obj+0x100/0x100 ffff88004117f1c8\n […] ? nft_table_lookup.part.0+0x255/0x300 ffff88004117f310\n […] ? nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f358\n […] nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f360\n […] ? nf_tables_addchain.constprop.0+0x1fc0/0x1fc0 ffff88004117f458\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f488\n […] ? lock_acquire+0x16f/0x320 ffff88004117f490\n […] ? find_held_lock+0x3b/0xe0 ffff88004117f4b0\n […] ? __nla_parse+0x45/0x80 ffff88004117f500\n […] nfnetlink_rcv_batch+0xbca/0x19a0 ffff88004117f550\n […] ? nfnetlink_net_exit_batch+0x120/0x120 ffff88004117f618\n […] ? __sanitizer_cov_trace_switch+0x63/0xe0 ffff88004117f720\n […] ? gr_acl_handle_mmap+0x1c4/0x320 ffff88004117f7c0\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f7e8\n […] ? gr_is_capable+0x6f/0xe0 ffff88004117f830\n […] ? __nla_parse+0x45/0x80 ffff88004117f860\n […] ? skb_pull+0x103/0x1a0 ffff88004117f880\n […] nfnetlink_rcv+0x3db/0x4a0 ffff88004117f8b0\n […] ? nfnetlink_rcv_batch+0x19a0/0x19a0 ffff88004117f8d8\n […] ? netlink_lookup+0xe2/0x240 ffff88004117f900\n […] netlink_unicast+0x74b/0xb00 ffff88004117f930\n […] ? netlink_attachskb+0xb20/0xb20 ffff88004117f980\n […] ? __check_object_size+0x3e/0xaa0 ffff88004117f998\n […] ? security_netlink_send+0x51/0x160 ffff88004117f9c8\n […] netlink_sendmsg+0xa03/0x1200 ffff88004117f9f8\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fa70\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fac8\n […] ? ____sys_sendmsg+0xe2a/0x1040 ffff88004117faf8\n […] ____sys_sendmsg+0xe2a/0x1040 ffff88004117fb00\n […] ? kernel_recvmsg+0x300/0x300 ffff88004117fb60\n […] ? reacquire_held_locks+0xe9/0x260 ffff88004117fbc8\n […] ___sys_sendmsg+0x138/0x200 ffff88004117fbf8\n […] ? do_recvmmsg+0x7e0/0x7e0 ffff88004117fc30\n […] ? lockdep_hardirqs_on_prepare+0x101/0x1e0 ffff88004117fc50\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd20\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd58\n […] ? find_held_lock+0x3b/0xe0 ffff88004117fd70\n […] __sys_sendmsg+0x17a/0x260 ffff88004117fdc8\n […] ? __sys_sendmsg_sock+0x80/0x80 ffff88004117fdf0\n […] ? syscall_trace_enter+0x15e/0x2c0 ffff88004117fe98\n […] do_syscall_64+0x7d/0x400 ffff88004117fec8\n […] entry_SYSCALL_64_safe_stack+0x4a/0x60 ffff88004117fef8\n </TASK>\n==================================================================\n\nThe out-of-bounds report, though, is a red herring as it is f\n---truncated---","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:22:15","updated_at":"2026-08-17 06:19:08"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/eb14aba91163c33d8c99f9d7c06690e08b56a250","name":"https://git.kernel.org/stable/c/eb14aba91163c33d8c99f9d7c06690e08b56a250","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/359d8ff97362a4662356104540e4814bff9dad7c","name":"https://git.kernel.org/stable/c/359d8ff97362a4662356104540e4814bff9dad7c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e794f633021defcfa98e17d73b955cd07590831f","name":"https://git.kernel.org/stable/c/e794f633021defcfa98e17d73b955cd07590831f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/069cfe3de2a5e16069485893cd04665ab769c1d8","name":"https://git.kernel.org/stable/c/069cfe3de2a5e16069485893cd04665ab769c1d8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/87f7a720de2545fdac29c85acb7163676feacdaf","name":"https://git.kernel.org/stable/c/87f7a720de2545fdac29c85acb7163676feacdaf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a73e7ac3f3b69e9581ec7bfd889ff3e9b8c773f7","name":"https://git.kernel.org/stable/c/a73e7ac3f3b69e9581ec7bfd889ff3e9b8c773f7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72419","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72419","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cbc1dd5b659f5a2c3cba88b197b7443679bb35a0 359d8ff97362a4662356104540e4814bff9dad7c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cbc1dd5b659f5a2c3cba88b197b7443679bb35a0 87f7a720de2545fdac29c85acb7163676feacdaf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cbc1dd5b659f5a2c3cba88b197b7443679bb35a0 e794f633021defcfa98e17d73b955cd07590831f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cbc1dd5b659f5a2c3cba88b197b7443679bb35a0 a73e7ac3f3b69e9581ec7bfd889ff3e9b8c773f7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cbc1dd5b659f5a2c3cba88b197b7443679bb35a0 eb14aba91163c33d8c99f9d7c06690e08b56a250 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cbc1dd5b659f5a2c3cba88b197b7443679bb35a0 069cfe3de2a5e16069485893cd04665ab769c1d8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72419","cve":"CVE-2026-72419","epss":"0.001640000","percentile":"0.060830000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/netfilter/nf_nat_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"359d8ff97362a4662356104540e4814bff9dad7c","status":"affected","version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","versionType":"git"},{"lessThan":"87f7a720de2545fdac29c85acb7163676feacdaf","status":"affected","version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","versionType":"git"},{"lessThan":"e794f633021defcfa98e17d73b955cd07590831f","status":"affected","version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","versionType":"git"},{"lessThan":"a73e7ac3f3b69e9581ec7bfd889ff3e9b8c773f7","status":"affected","version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","versionType":"git"},{"lessThan":"eb14aba91163c33d8c99f9d7c06690e08b56a250","status":"affected","version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","versionType":"git"},{"lessThan":"069cfe3de2a5e16069485893cd04665ab769c1d8","status":"affected","version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/netfilter/nf_nat_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.1"},{"lessThan":"6.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"6.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"6.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"6.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"6.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"6.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()\n\nWe ran into below KASAN splat, which is mostly uninteresting, beside\nfor having nf_nat_register_fn() in the call chain as a cause for the\noffending access:\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in nf_nat_register_fn+0x5f9/0x640\nRead of size 8 at addr ffff890031e54c20 by task iptables/9510\n\nCPU: 0 UID: 0 PID: 9510 Comm: iptables Not tainted 6.18.18-grsec-full-20260320181326 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <TASK>\n […] dump_stack_lvl+0xee/0x160 ffff88004117eeb8\n […] print_report+0x6e/0x640 ffff88004117eee0\n […] ? __phys_addr+0x8e/0x140 ffff88004117eef0\n […] ? kasan_addr_to_slab+0x51/0xe0 ffff88004117ef08\n […] ? complete_report_info+0xec/0x1c0 ffff88004117ef20\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef48\n […] kasan_report+0xbc/0x140 ffff88004117ef50\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef90\n […] nf_nat_register_fn+0x5f9/0x640 ffff88004117eff8\n […] ? nf_nat_icmp_reply_translation+0x6e0/0x6e0 ffff88004117f070\n […] nf_tables_register_hook.part.0+0xa0/0x220 ffff88004117f080\n […] nf_tables_addchain.constprop.0+0x1054/0x1fc0 ffff88004117f0b8\n […] ? nft_chain_lookup.part.0+0x4ce/0xac0 ffff88004117f130\n […] ? nf_tables_abort+0x3d80/0x3d80 ffff88004117f190\n […] ? nf_tables_dumpreset_obj+0x100/0x100 ffff88004117f1c8\n […] ? nft_table_lookup.part.0+0x255/0x300 ffff88004117f310\n […] ? nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f358\n […] nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f360\n […] ? nf_tables_addchain.constprop.0+0x1fc0/0x1fc0 ffff88004117f458\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f488\n […] ? lock_acquire+0x16f/0x320 ffff88004117f490\n […] ? find_held_lock+0x3b/0xe0 ffff88004117f4b0\n […] ? __nla_parse+0x45/0x80 ffff88004117f500\n […] nfnetlink_rcv_batch+0xbca/0x19a0 ffff88004117f550\n […] ? nfnetlink_net_exit_batch+0x120/0x120 ffff88004117f618\n […] ? __sanitizer_cov_trace_switch+0x63/0xe0 ffff88004117f720\n […] ? gr_acl_handle_mmap+0x1c4/0x320 ffff88004117f7c0\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f7e8\n […] ? gr_is_capable+0x6f/0xe0 ffff88004117f830\n […] ? __nla_parse+0x45/0x80 ffff88004117f860\n […] ? skb_pull+0x103/0x1a0 ffff88004117f880\n […] nfnetlink_rcv+0x3db/0x4a0 ffff88004117f8b0\n […] ? nfnetlink_rcv_batch+0x19a0/0x19a0 ffff88004117f8d8\n […] ? netlink_lookup+0xe2/0x240 ffff88004117f900\n […] netlink_unicast+0x74b/0xb00 ffff88004117f930\n […] ? netlink_attachskb+0xb20/0xb20 ffff88004117f980\n […] ? __check_object_size+0x3e/0xaa0 ffff88004117f998\n […] ? security_netlink_send+0x51/0x160 ffff88004117f9c8\n […] netlink_sendmsg+0xa03/0x1200 ffff88004117f9f8\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fa70\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fac8\n […] ? ____sys_sendmsg+0xe2a/0x1040 ffff88004117faf8\n […] ____sys_sendmsg+0xe2a/0x1040 ffff88004117fb00\n […] ? kernel_recvmsg+0x300/0x300 ffff88004117fb60\n […] ? reacquire_held_locks+0xe9/0x260 ffff88004117fbc8\n […] ___sys_sendmsg+0x138/0x200 ffff88004117fbf8\n […] ? do_recvmmsg+0x7e0/0x7e0 ffff88004117fc30\n […] ? lockdep_hardirqs_on_prepare+0x101/0x1e0 ffff88004117fc50\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd20\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd58\n […] ? find_held_lock+0x3b/0xe0 ffff88004117fd70\n […] __sys_sendmsg+0x17a/0x260 ffff88004117fdc8\n […] ? __sys_sendmsg_sock+0x80/0x80 ffff88004117fdf0\n […] ? syscall_trace_enter+0x15e/0x2c0 ffff88004117fe98\n […] do_syscall_64+0x7d/0x400 ffff88004117fec8\n […] entry_SYSCALL_64_safe_stack+0x4a/0x60 ffff88004117fef8\n </TASK>\n==================================================================\n\nThe out-of-bounds report, though, is a red herring as it is f\n---truncated---"}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached via the netfilter netlink path (sendmsg on NETLINK_NETFILTER) when creating an nftables NAT chain; nf_tables_newchain -> nf_tables_register_hook -> nf_nat_register_fn. This is a local syscall/configuration interface, not remote packet handling.\nAC:L - Once nf_nat built-in init has failed and another per-net consumer reuses the stale nat_net_id, a CAP_NET_ADMIN caller can deterministically trigger the type confusion by adding/removing a NAT chain; no race, memory-layout gamble, or victim interaction is required.\nPR:L - nfnetlink_rcv requires CAP_NET_ADMIN via netlink_net_capable(); on systems with user namespaces this capability is available to an unprivileged local user (e.g. unshare -Urn), not only init-namespace root.\nUI:N - Exploitation is performed entirely by the attacker configuring nftables NAT chains over netlink; no action by another user or administrator is required beyond the attacker’s own netfilter setup.\nS:U - Impact is kernel memory corruption and privilege escalation within the same host/kernel security domain; it does not cross a VM, container-to-host, or IOMMU boundary by itself.\nC:H - Stale nat_net_id makes net_generic() return a synproxy_net (24 bytes) misinterpreted as nat_net (176 bytes), causing slab out-of-bounds reads; KASAN confirmed an 8-byte OOB read and type confusion can expose adjacent per-net/kernel heap data.\nI:H - nf_nat_register_fn()/unregister_fn() write nat_hook_ops pointers, user counters, and hook entry tables through the mis-typed smaller structure, corrupting adjacent per-net memory and enabling further arbitrary write/control-flow hijack primitives.\nA:H - The mis-typed per-net access triggers KASAN slab-out-of-bounds faults and can kernel oops/panic during NAT hook registration; corrupted synproxy/per-net state can also crash or hang the system on subsequent netfilter activity."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:43:59.432Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/359d8ff97362a4662356104540e4814bff9dad7c"},{"url":"https://git.kernel.org/stable/c/87f7a720de2545fdac29c85acb7163676feacdaf"},{"url":"https://git.kernel.org/stable/c/e794f633021defcfa98e17d73b955cd07590831f"},{"url":"https://git.kernel.org/stable/c/a73e7ac3f3b69e9581ec7bfd889ff3e9b8c773f7"},{"url":"https://git.kernel.org/stable/c/eb14aba91163c33d8c99f9d7c06690e08b56a250"},{"url":"https://git.kernel.org/stable/c/069cfe3de2a5e16069485893cd04665ab769c1d8"}],"title":"netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72419","datePublished":"2026-08-15T05:56:39.126Z","dateReserved":"2026-08-09T03:40:39.927Z","dateUpdated":"2026-08-17T05:43:59.432Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:22:15","lastModifiedDate":"2026-08-17 06:19:08","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72419","Ordinal":"1","Title":"netfilter: nf_nat: avoid invalid nat_net pointer use on failed n","CVE":"CVE-2026-72419","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72419","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()\n\nWe ran into below KASAN splat, which is mostly uninteresting, beside\nfor having nf_nat_register_fn() in the call chain as a cause for the\noffending access:\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in nf_nat_register_fn+0x5f9/0x640\nRead of size 8 at addr ffff890031e54c20 by task iptables/9510\n\nCPU: 0 UID: 0 PID: 9510 Comm: iptables Not tainted 6.18.18-grsec-full-20260320181326 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <TASK>\n […] dump_stack_lvl+0xee/0x160 ffff88004117eeb8\n […] print_report+0x6e/0x640 ffff88004117eee0\n […] ? __phys_addr+0x8e/0x140 ffff88004117eef0\n […] ? kasan_addr_to_slab+0x51/0xe0 ffff88004117ef08\n […] ? complete_report_info+0xec/0x1c0 ffff88004117ef20\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef48\n […] kasan_report+0xbc/0x140 ffff88004117ef50\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef90\n […] nf_nat_register_fn+0x5f9/0x640 ffff88004117eff8\n […] ? nf_nat_icmp_reply_translation+0x6e0/0x6e0 ffff88004117f070\n […] nf_tables_register_hook.part.0+0xa0/0x220 ffff88004117f080\n […] nf_tables_addchain.constprop.0+0x1054/0x1fc0 ffff88004117f0b8\n […] ? nft_chain_lookup.part.0+0x4ce/0xac0 ffff88004117f130\n […] ? nf_tables_abort+0x3d80/0x3d80 ffff88004117f190\n […] ? nf_tables_dumpreset_obj+0x100/0x100 ffff88004117f1c8\n […] ? nft_table_lookup.part.0+0x255/0x300 ffff88004117f310\n […] ? nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f358\n […] nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f360\n […] ? nf_tables_addchain.constprop.0+0x1fc0/0x1fc0 ffff88004117f458\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f488\n […] ? lock_acquire+0x16f/0x320 ffff88004117f490\n […] ? find_held_lock+0x3b/0xe0 ffff88004117f4b0\n […] ? __nla_parse+0x45/0x80 ffff88004117f500\n […] nfnetlink_rcv_batch+0xbca/0x19a0 ffff88004117f550\n […] ? nfnetlink_net_exit_batch+0x120/0x120 ffff88004117f618\n […] ? __sanitizer_cov_trace_switch+0x63/0xe0 ffff88004117f720\n […] ? gr_acl_handle_mmap+0x1c4/0x320 ffff88004117f7c0\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f7e8\n […] ? gr_is_capable+0x6f/0xe0 ffff88004117f830\n […] ? __nla_parse+0x45/0x80 ffff88004117f860\n […] ? skb_pull+0x103/0x1a0 ffff88004117f880\n […] nfnetlink_rcv+0x3db/0x4a0 ffff88004117f8b0\n […] ? nfnetlink_rcv_batch+0x19a0/0x19a0 ffff88004117f8d8\n […] ? netlink_lookup+0xe2/0x240 ffff88004117f900\n […] netlink_unicast+0x74b/0xb00 ffff88004117f930\n […] ? netlink_attachskb+0xb20/0xb20 ffff88004117f980\n […] ? __check_object_size+0x3e/0xaa0 ffff88004117f998\n […] ? security_netlink_send+0x51/0x160 ffff88004117f9c8\n […] netlink_sendmsg+0xa03/0x1200 ffff88004117f9f8\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fa70\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fac8\n […] ? ____sys_sendmsg+0xe2a/0x1040 ffff88004117faf8\n […] ____sys_sendmsg+0xe2a/0x1040 ffff88004117fb00\n […] ? kernel_recvmsg+0x300/0x300 ffff88004117fb60\n […] ? reacquire_held_locks+0xe9/0x260 ffff88004117fbc8\n […] ___sys_sendmsg+0x138/0x200 ffff88004117fbf8\n […] ? do_recvmmsg+0x7e0/0x7e0 ffff88004117fc30\n […] ? lockdep_hardirqs_on_prepare+0x101/0x1e0 ffff88004117fc50\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd20\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd58\n […] ? find_held_lock+0x3b/0xe0 ffff88004117fd70\n […] __sys_sendmsg+0x17a/0x260 ffff88004117fdc8\n […] ? __sys_sendmsg_sock+0x80/0x80 ffff88004117fdf0\n […] ? syscall_trace_enter+0x15e/0x2c0 ffff88004117fe98\n […] do_syscall_64+0x7d/0x400 ffff88004117fec8\n […] entry_SYSCALL_64_safe_stack+0x4a/0x60 ffff88004117fef8\n </TASK>\n==================================================================\n\nThe out-of-bounds report, though, is a red herring as it is f\n---truncated---","Type":"Description","Title":"netfilter: nf_nat: avoid invalid nat_net pointer use on failed n"}]}}}