CVE-2026-98321

Summary

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_nat: unregister and release hooks on error

If nf_hook_entries_insert_raw() fails, the NAT hooks get never released, resulting in a memleak.

Postpone setting nat_proto_net->nat_hook_ops when the hooks are registered to simplify the error path to decide whether the nat hooks need unwinding.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1cd472bf036ca038e783ef5f058f54e45b7e8180 < 79084567cd082fb4482e1ea457580e7d6504dd99affected
LinuxLinux1cd472bf036ca038e783ef5f058f54e45b7e8180 < df80342f4bfc023ad7d6703df5e27f583ff0cb8daffected
LinuxLinux1cd472bf036ca038e783ef5f058f54e45b7e8180 < cbdd39ce42530a193c56beb206a3356cb6d01016affected
LinuxLinux4.18affected
LinuxLinux0 < 4.18unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References