---
id: CVE-2026-43026
title: 'netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent

  ctnetlink_alloc_expect() allocates expectations from a non-zeroing
  slab cache via nf_ct_expect_…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    a5a89db6981a1ddf2314bf50cb49db5a3146185f
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    1c2ebdeff8d088a2e47ae25d7b38447249adace2
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    a64b7bf84b4d5ea54218c5d374ec87fff9000f43
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    2898080c054ea4d6ddfaaf21bbedbc229a9a8376
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    fd002ff2ea030cbfb0188a11b3c60ce7f84485f4
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    929f7a9a7aad9404a5867216c3f8738232355b38
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    bff0f4f06f12d6d9bc565a3e1378abd4f6f5ce36
  - >-
    Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb <
    35177c6877134a21315f37d57a5577846225623e
  - Linux 3.4
published: '2026-05-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:48:26.219Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-43026'
references:
  - url: 'https://git.kernel.org/stable/c/a5a89db6981a1ddf2314bf50cb49db5a3146185f'
  - url: 'https://git.kernel.org/stable/c/1c2ebdeff8d088a2e47ae25d7b38447249adace2'
  - url: 'https://git.kernel.org/stable/c/a64b7bf84b4d5ea54218c5d374ec87fff9000f43'
  - url: 'https://git.kernel.org/stable/c/2898080c054ea4d6ddfaaf21bbedbc229a9a8376'
  - url: 'https://git.kernel.org/stable/c/fd002ff2ea030cbfb0188a11b3c60ce7f84485f4'
  - url: 'https://git.kernel.org/stable/c/929f7a9a7aad9404a5867216c3f8738232355b38'
  - url: 'https://git.kernel.org/stable/c/bff0f4f06f12d6d9bc565a3e1378abd4f6f5ce36'
  - url: 'https://git.kernel.org/stable/c/35177c6877134a21315f37d57a5577846225623e'
tags:
  - cve.org
epss: 0.00171
epssPercentile: 0.05627
ingestedAt: '2026-09-08T15:33:26.989Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent

ctnetlink_alloc_expect() allocates expectations from a non-zeroing
slab cache via nf_ct_expect_alloc().  When CTA_EXPECT_NAT is not
present in the netlink message, saved_addr and saved_proto are
never initialized.  Stale data from a previous slab occupant can
then be dumped to userspace by ctnetlink_exp_dump_expect(), which
checks these fields to decide whether to emit CTA_EXPECT_NAT.

The safe sibling nf_ct_expect_init(), used by the packet path,
explicitly zeroes these fields.

Zero saved_addr, saved_proto and dir in the else branch, guarded
by IS_ENABLED(CONFIG_NF_NAT) since these fields only exist when
NAT is enabled.

Confirmed by priming the expect slab with NAT-bearing expectations,
freeing them, creating a new expectation without CTA_EXPECT_NAT,
and observing that the ctnetlink dump emits a spurious
CTA_EXPECT_NAT containing stale data from the prior allocation.

## Affected

- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < a5a89db6981a1ddf2314bf50cb49db5a3146185f`
- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < 1c2ebdeff8d088a2e47ae25d7b38447249adace2`
- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < a64b7bf84b4d5ea54218c5d374ec87fff9000f43`
- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < 2898080c054ea4d6ddfaaf21bbedbc229a9a8376`
- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < fd002ff2ea030cbfb0188a11b3c60ce7f84485f4`
- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < 929f7a9a7aad9404a5867216c3f8738232355b38`
- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < bff0f4f06f12d6d9bc565a3e1378abd4f6f5ce36`
- `Linux >= 076a0ca02644657b13e4af363f487ced2942e9cb < 35177c6877134a21315f37d57a5577846225623e`
- `Linux 3.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
