CVE-2026-100070 Overview
CVE-2026-100070 affects the Linux kernel's netfilter subsystem, specifically the nf_nat_sip Session Initiation Protocol (SIP) Network Address Translation (NAT) helper. The vulnerability stems from a stale offset variable (coff) after map_addr() mangles packet length during NAT rewriting. When the translated public IP string differs in length from the internal IP, the parser may skip bytes and miss subsequent SIP Contact headers. This can cause the kernel to leave later Contact headers un-translated, exposing internal network addressing to external parties.
Critical Impact
Un-translated SIP Contact headers can leak internal network details and private IP addresses to external SIP endpoints.
Affected Products
- Linux kernel builds with nf_nat_sip SIP NAT helper enabled
- Stable kernel branches prior to the fix commits referenced in the kernel changelogs
- Distributions shipping affected kernels until vendor backports land
Discovery Timeline
- 2026-09-25 - CVE-2026-100070 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100070
Vulnerability Analysis
The nf_nat_sip module rewrites SIP message fields so NAT'd endpoints can receive return traffic. During processing, the helper tracks a cumulative offset (coff) that points into the SIP payload relative to subsequent Contact headers. When map_addr() substitutes an internal address with a public one of a different length, the packet length changes but coff is not adjusted.
If the packet shrinks, coff overshoots the correct position in the mangled packet. The next call to ct_sip_parse_header_uri() begins parsing past the intended header boundary. The parser then silently skips bytes and may fail to locate subsequent Contact headers that require NAT translation.
Root Cause
The root cause is an input validation and boundary tracking error. The code assumed packet length would remain static across map_addr() invocations. When mangling shortens or lengthens the packet, the offset variable is not rewound to reflect the new buffer layout, producing an inconsistent view of the SIP message.
Attack Vector
An attacker who can send or influence SIP traffic traversing a vulnerable Linux NAT device may receive responses containing un-translated internal addresses. The flaw does not grant code execution. It enables information disclosure of internal network topology by causing the kernel to forward private addressing in SIP Contact headers that bypassed translation.
The vulnerability is triggered by crafted SIP messages containing multiple Contact headers where NAT translation changes the overall payload length. No authentication is required against the NAT device itself; the attacker only needs to participate in a SIP exchange routed through it.
Detection Methods for CVE-2026-100070
Indicators of Compromise
- SIP responses leaving the perimeter that contain RFC 1918 private IP addresses (for example 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) in Contact headers
- SIP registrations or INVITEs with multiple Contact headers where only the first is rewritten to the public address
- Unexpected re-INVITE failures or one-way audio caused by malformed Contact header offsets
Detection Strategies
- Inspect SIP traffic at the WAN boundary with a deep packet inspection tool and alert on internal addresses in any SIP header
- Correlate kernel version information from uname -r against the patch commits listed in the kernel changelogs for CVE-2026-100070
- Review conntrack and nf_nat logs for SIP flows showing size deltas between pre- and post-mangle packet counts
Monitoring Recommendations
- Enable packet capture on SIP-bearing interfaces and periodically audit outbound Contact headers for private address disclosure
- Track Linux kernel package versions across the fleet to confirm patched builds are deployed on NAT gateways and session border controllers
- Monitor SIP session integrity metrics such as registration failures and media path mismatches that can indicate skipped header translation
How to Mitigate CVE-2026-100070
Immediate Actions Required
- Apply the upstream kernel fixes referenced in the kernel changelog commits (0f4d30e, 16aecbe, 2703f5e, 668cc1c3, 6828aca, 810da5a, c408d41, e70d48f)
- Rebuild or update distribution kernel packages on all Linux hosts performing SIP NAT, including firewalls, routers, and session border controllers
- Reboot affected systems after kernel updates to load the patched nf_nat_sip module
Patch Information
The fix rewinds the coff offset when map_addr() changes the packet length, ensuring subsequent ct_sip_parse_header_uri() calls operate on correct byte positions. Patched commits are available in the stable kernel tree. See the Kernel Change Log Entry 0f4d30e and the companion stable backports listed in the references section for the canonical fix.
Workarounds
- Disable the nf_nat_sip connection tracking helper where SIP ALG functionality is not required by unloading the nf_nat_sip and nf_conntrack_sip modules
- Route SIP traffic through a dedicated application-layer SIP proxy or session border controller that performs NAT translation outside the kernel helper
- Enforce egress filtering that blocks SIP messages containing RFC 1918 addresses from leaving the network perimeter
# Unload SIP NAT helpers until the kernel is patched
sudo modprobe -r nf_nat_sip
sudo modprobe -r nf_conntrack_sip
# Prevent automatic loading at boot
echo "blacklist nf_nat_sip" | sudo tee /etc/modprobe.d/blacklist-nf_nat_sip.conf
echo "blacklist nf_conntrack_sip" | sudo tee -a /etc/modprobe.d/blacklist-nf_nat_sip.conf
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.