CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-53002

Critical · CVSS 9.8

Linux Kernel — Stack out-of-bounds write (CWE-787) via sprintf in netfilter conntrack SIP NAT helper

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-787, CWE-787

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_content_len() while at it. BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270 Write of size 1 at addr [..] vsnprintf+0xea5/0x1270 sprintf+0xb1/0xe0 mangle_content_len+0x1ac/0x280 nf_nat_sdp_session+0x1cc/0x240 process_sdp+0x8f8/0xb80 process_invite_request+0x108/0x2b0 process_sip_msg+0x5da/0xf50 sip_help_tcp+0x45e/0x780 nf_confirm+0x34d/0x990 [..]

Search profile — drives PoC discovery

Symbols mangle_content_lennf_nat_sdp_sessionprocess_sdpprocess_invite_requestprocess_sip_msgsip_help_tcpnf_confirmvsnprintfsprintfscnprintfnf_nat_sipnf_conntrack_sip
Keywords CVE-2026-53002Linux kernel netfilter conntrack sprintf stack-out-of-boundsKASAN stack-out-of-bounds mangle_content_lennf_nat_sdp_session exploitnetfilter SIP NAT helper buffer overflownf_conntrack_sip mangle_content_len scnprintfLinux kernel CWE-787 netfilter PoC
Versions: Fixed in commits: 1c9fb8aeed06, 2f793ba78470, 6bbf829b4c1b, 6e7066bdb481, 8e3be0d12615

Affected packages

Linux Kernel 2.6.20 → 5.10.258
Linux Kernel 5.11.0 → 5.15.209
Linux Kernel 5.16.0 → 6.1.175
Linux Kernel 6.13.0 → 6.18.33
Linux Kernel 6.19.0 → 7.0.10
Linux Kernel 6.2.0 → 6.6.141
Linux Kernel 6.7.0 → 6.12.91

References

Status: enriched · ingested 2026-07-11T00:00:26.000Z · profiled 2026-07-11T00:30:26.000Z