CVE-2026-98321 Overview
CVE-2026-98321 is a memory leak vulnerability in the Linux kernel's netfilter Network Address Translation (NAT) subsystem. The flaw resides in the nf_nat component, where NAT hooks are not properly released when nf_hook_entries_insert_raw() fails during registration. The kernel maintainers resolved the issue by postponing the assignment of nat_proto_net->nat_hook_ops until after hooks are successfully registered, simplifying the error path.
Critical Impact
Repeated failures in NAT hook registration can exhaust kernel memory over time, leading to resource depletion and potential denial of service on affected Linux systems.
Affected Products
- Linux kernel (netfilter nf_nat subsystem)
- Distributions shipping affected mainline and stable kernel versions
- Systems using NAT hooks via netfilter
Discovery Timeline
- 2026-10-06 - CVE CVE-2026-98321 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-98321
Vulnerability Analysis
The vulnerability is a memory leak in the netfilter NAT hook registration path. When the kernel attempts to install NAT hooks via nf_hook_entries_insert_raw(), a failure in that call leaves previously allocated NAT hook structures unreleased. The leaked allocations accumulate across repeated failures, consuming kernel memory that cannot be reclaimed without a reboot.
The upstream fix reorders the registration logic so that nat_proto_net->nat_hook_ops is assigned only after successful hook installation. This change makes the error path deterministic and ensures the cleanup code can correctly decide whether unwinding is required. The fix is tracked across multiple stable branches via commits 79084567, cbdd39ce4, and df80342f4.
Root Cause
The root cause is improper error handling in the NAT hook registration sequence. The pointer nat_proto_net->nat_hook_ops was being set before the hooks were confirmed as registered. When nf_hook_entries_insert_raw() returned an error, the cleanup logic could not distinguish between partially and fully registered state, so it skipped releasing the hooks.
Attack Vector
The vulnerability requires local privileges capable of triggering NAT hook registration operations, such as namespace creation or iptables/nftables configuration changes within a network namespace. An actor able to repeatedly induce the failure condition in nf_hook_entries_insert_raw() can gradually exhaust kernel memory. This classifies as a Kernel Vulnerability leading to Memory Leak and potential Denial of Service.
No verified public exploit code is available for CVE-2026-98321. See the kernel commit references for the technical fix details.
Detection Methods for CVE-2026-98321
Indicators of Compromise
- Unexpected growth in kernel slab allocations related to netfilter structures observed through /proc/slabinfo.
- Repeated failures of nf_hook_entries_insert_raw() recorded in dmesg or kernel audit logs.
- Progressive increase in Slab and SUnreclaim values in /proc/meminfo without corresponding workload growth.
Detection Strategies
- Monitor kernel memory counters over time and alert on sustained upward trends uncorrelated with legitimate workloads.
- Track creation and teardown of network namespaces, especially in multi-tenant or container environments where NAT hook registration occurs frequently.
- Correlate netfilter configuration errors with memory growth to identify systems hitting the failure path.
Monitoring Recommendations
- Enable kernel memory leak detection via kmemleak on test systems to validate patched builds.
- Collect node-level telemetry on MemAvailable, Slab, and container runtime events for long-running hosts.
- Audit syscalls and privileged operations that create or modify netfilter rules in production namespaces.
How to Mitigate CVE-2026-98321
Immediate Actions Required
- Apply the stable kernel updates containing commits 79084567cd08, cbdd39ce4253, and df80342f4bfc from kernel.org.
- Restrict CAP_NET_ADMIN and user namespace creation to trusted principals to limit who can trigger NAT hook registration.
- Reboot hosts exhibiting symptoms of kernel memory exhaustion after patching to reclaim leaked memory.
Patch Information
The fix is available upstream in the Linux kernel stable tree. Review the kernel commits 79084567cd08, cbdd39ce4253, and df80342f4bfc for the exact code changes. Deploy vendor-supplied kernel packages that incorporate these patches.
Workarounds
- Limit the frequency of netfilter configuration changes in environments that cannot be patched immediately.
- Disable or constrain unprivileged user namespaces where feasible using kernel.unprivileged_userns_clone=0.
- Monitor and recycle long-lived hosts that show sustained kernel slab growth until patches are applied.
# Configuration example
# Restrict unprivileged user namespace creation (Debian/Ubuntu)
sysctl -w kernel.unprivileged_userns_clone=0
# Verify installed kernel version includes the fix
uname -r
# Inspect netfilter-related slab usage
grep -E 'nf_|netfilter' /proc/slabinfo
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.