CVE-2026-98322

Source
https://cve.org/CVERecord?id=CVE-2026-98322
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98322.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98322
Downstream
Published
2026-10-06T08:46:16Z
Modified
2026-10-07T02:47:32Z
Summary
netfilter: nft_nat: fully initialise new_addr in netmap setup
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_nat: fully initialise new_addr in netmap setup

nft_nat_setup_netmap() builds the mapped address in an on-stack union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip member and the loop runs a single 32-bit iteration, but it then copies the whole 16-byte union into range->min_addr and range->max_addr, so the upper 12 bytes reach nf_nat_setup_info() uninitialised.

KMSAN reports an uninit-value in nf_nat_setup_info() reached from nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected.

Zero-initialise new_addr.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98322.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3ff7ddb1353da9b535e65702704cbadea1da9a00
Fixed
29365695842db0a97b701a43a09fad1b4f7ecf3e
Fixed
7b9380c38c2fd2189416fa602bdbc5c8523b84b2
Fixed
eb2030137dba3b59cbb5057a33af70488d6bc231
Fixed
e4982c489ee359162eee3ece1fb36082648464a5
Fixed
161f5860c92a8ec80b6bdff16e79d70dcd8afc5a
Fixed
0ce42c7b84032335abff9eac43762e4ca8224451
Fixed
1c43f5db482f74b41987c39c9c375a5e767556eb
Fixed
d313499df66159b4b7971d760d16729598ab7e5a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98322.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.8.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98322.json"