{"api_version":"1","generated_at":"2026-08-29T12:12:57+00:00","cve":"CVE-2026-80664","urls":{"html":"https://cve.report/CVE-2026-80664","api":"https://cve.report/api/cve/CVE-2026-80664.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80664","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80664"},"summary":{"title":"netfilter: xt_nat: reject unsupported target families","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_nat: reject unsupported target families\n\nxt_nat SNAT and DNAT target handlers assume IP-family conntrack state\nis present and can dereference a NULL pointer when instantiated from an\nunsupported family through nft_compat. A bridge-family compat rule can\ntherefore trigger a NULL-dereference in nf_nat_setup_info().\n\nReject non-IP families in xt_nat_checkentry() so unsupported targets\ncannot be installed. Keep NFPROTO_INET allowed for valid inet NAT\ncompat users and leave the runtime fast path unchanged.\n\n[ The crash was fixed via\n  9dbba7e694ec (\"netfilter: nft_compat: ebtables emulation must reject non-bridge targets\"),\n  so this patch is no longer critical.\n  Nevertheless, NAT is only relevant for ipv4/ipv6, so this extra\n  family check is a good idea in any case. ]","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-28 08:16:51","updated_at":"2026-08-29 07:16:48"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","data":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd","name":"https://git.kernel.org/stable/c/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/679ced28a9dc2f6dc679eb05027d779693e60902","name":"https://git.kernel.org/stable/c/679ced28a9dc2f6dc679eb05027d779693e60902","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82","name":"https://git.kernel.org/stable/c/0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/49abe564391411057a26a9a943c8e17867c3b9b4","name":"https://git.kernel.org/stable/c/49abe564391411057a26a9a943c8e17867c3b9b4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e35c048d7511e9d4c2a537b8a231c49606e97c16","name":"https://git.kernel.org/stable/c/e35c048d7511e9d4c2a537b8a231c49606e97c16","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ec88fa71c82072e9189983b05b499d3507550271","name":"https://git.kernel.org/stable/c/ec88fa71c82072e9189983b05b499d3507550271","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777","name":"https://git.kernel.org/stable/c/4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a842dab87cab29f2a5798a47b2dc5e6a449950bf","name":"https://git.kernel.org/stable/c/a842dab87cab29f2a5798a47b2dc5e6a449950bf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80664","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80664","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 49abe564391411057a26a9a943c8e17867c3b9b4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 a842dab87cab29f2a5798a47b2dc5e6a449950bf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 e35c048d7511e9d4c2a537b8a231c49606e97c16 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 679ced28a9dc2f6dc679eb05027d779693e60902 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 ec88fa71c82072e9189983b05b499d3507550271 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c7232c9979cba684c50b64c513c4a83c9aa70563 5d1a2240935ea47e2673d0ea17fdb058e4dc91dd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.7","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.7 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80664","cve":"CVE-2026-80664","epss":"0.001760000","percentile":"0.072310000","score_date":"2026-08-28","updated_at":"2026-08-29 00:12:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/netfilter/xt_nat.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"49abe564391411057a26a9a943c8e17867c3b9b4","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"},{"lessThan":"0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"},{"lessThan":"4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"},{"lessThan":"a842dab87cab29f2a5798a47b2dc5e6a449950bf","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"},{"lessThan":"e35c048d7511e9d4c2a537b8a231c49606e97c16","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"},{"lessThan":"679ced28a9dc2f6dc679eb05027d779693e60902","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"},{"lessThan":"ec88fa71c82072e9189983b05b499d3507550271","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"},{"lessThan":"5d1a2240935ea47e2673d0ea17fdb058e4dc91dd","status":"affected","version":"c7232c9979cba684c50b64c513c4a83c9aa70563","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/netfilter/xt_nat.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.7"},{"lessThan":"3.7","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"3.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"3.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"3.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"3.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"3.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"3.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"3.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"3.7","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_nat: reject unsupported target families\n\nxt_nat SNAT and DNAT target handlers assume IP-family conntrack state\nis present and can dereference a NULL pointer when instantiated from an\nunsupported family through nft_compat. A bridge-family compat rule can\ntherefore trigger a NULL-dereference in nf_nat_setup_info().\n\nReject non-IP families in xt_nat_checkentry() so unsupported targets\ncannot be installed. Keep NFPROTO_INET allowed for valid inet NAT\ncompat users and leave the runtime fast path unchanged.\n\n[ The crash was fixed via\n  9dbba7e694ec (\"netfilter: nft_compat: ebtables emulation must reject non-bridge targets\"),\n  so this patch is no longer critical.\n  Nevertheless, NAT is only relevant for ipv4/ipv6, so this extra\n  family check is a good idea in any case. ]"}],"metrics":[{"cvssV3_1":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires installing a bridge-family nft_compat SNAT/DNAT rule via NETLINK_NETFILTER (nftables netlink), a local syscall path; although matching bridge traffic can trigger evaluation, the vulnerable rule state cannot be created without local netfilter administration.\nAC:L - Once CAP_NET_ADMIN is held in the target network namespace, xt_request_find_target() deterministically resolves UNSPEC-family SNAT/DNAT rev 1/2 targets for bridge chains, and sending bridge traffic through the committed rule reliably reaches nf_nat_setup_info() with a NULL nf_conn from nf_ct_get().\nPR:L - All nfnetlink handlers are gated by netlink_net_capable(skb, CAP_NET_ADMIN), which checks capability in the socket network namespace user namespace; unprivileged local users routinely obtain CAP_NET_ADMIN via user and network namespaces (unshare -Urn), enabling installation of the malicious bridge compat rule.\nUI:N - No victim interaction is required beyond the attacker obtaining namespace-local CAP_NET_ADMIN, creating a bridge nftables chain with a compat SNAT/DNAT target, and delivering matching bridge traffic; no third-party actions such as mounting filesystems or opening files are needed.\nS:U - Impact is confined to the host kernel netfilter/NAT subsystem within the same security authority; this is not a VM escape, hypervisor boundary crossing, or IOMMU/DMA sandbox bypass, but standard in-kernel misbehavior from an invalid family/target pairing.\nC:L - The primary runtime failure is a NULL nf_conn dereference in nf_nat_setup_info(), and the surrounding nft_compat bridge/xtables semantic mismatch can leak limited kernel information via oops register dumps and crash logs readable by the local attacker who triggered the fault.\nI:H - Missing family validation lets IP-family NAT targets execute under bridge nft_compat semantics where nf_ct_get() yields NULL, constituting a type/family confusion that can corrupt netfilter verdict and NAT handling before faulting; mis-instantiated SNAT/DNAT targets should not run in bridge context at all.\nA:H - Passing bridge traffic through a bridge-family compat SNAT/DNAT rule causes nf_nat_setup_info() to dereference the NULL connection from nf_ct_get(), producing a kernel oops or panic; repeated matching traffic can retrigger the crash for sustained denial of service."}]}],"providerMetadata":{"dateUpdated":"2026-08-29T06:21:50.580Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/49abe564391411057a26a9a943c8e17867c3b9b4"},{"url":"https://git.kernel.org/stable/c/0afc9ad987c0faa80ab5f8d6e7815085ac8dbb82"},{"url":"https://git.kernel.org/stable/c/4fbc2bac02edabb665beb2aa87ca6f1e1d4c4777"},{"url":"https://git.kernel.org/stable/c/a842dab87cab29f2a5798a47b2dc5e6a449950bf"},{"url":"https://git.kernel.org/stable/c/e35c048d7511e9d4c2a537b8a231c49606e97c16"},{"url":"https://git.kernel.org/stable/c/679ced28a9dc2f6dc679eb05027d779693e60902"},{"url":"https://git.kernel.org/stable/c/ec88fa71c82072e9189983b05b499d3507550271"},{"url":"https://git.kernel.org/stable/c/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd"}],"title":"netfilter: xt_nat: reject unsupported target families","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80664","datePublished":"2026-08-28T06:49:07.478Z","dateReserved":"2026-08-26T14:34:25.781Z","dateUpdated":"2026-08-29T06:21:50.580Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-28 08:16:51","lastModifiedDate":"2026-08-29 07:16:48","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80664","Ordinal":"1","Title":"netfilter: xt_nat: reject unsupported target families","CVE":"CVE-2026-80664","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80664","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_nat: reject unsupported target families\n\nxt_nat SNAT and DNAT target handlers assume IP-family conntrack state\nis present and can dereference a NULL pointer when instantiated from an\nunsupported family through nft_compat. A bridge-family compat rule can\ntherefore trigger a NULL-dereference in nf_nat_setup_info().\n\nReject non-IP families in xt_nat_checkentry() so unsupported targets\ncannot be installed. Keep NFPROTO_INET allowed for valid inet NAT\ncompat users and leave the runtime fast path unchanged.\n\n[ The crash was fixed via\n  9dbba7e694ec (\"netfilter: nft_compat: ebtables emulation must reject non-bridge targets\"),\n  so this patch is no longer critical.\n  Nevertheless, NAT is only relevant for ipv4/ipv6, so this extra\n  family check is a good idea in any case. ]","Type":"Description","Title":"netfilter: xt_nat: reject unsupported target families"}]}}}