
CVE-2026-31427: Linux Kernel Use-After-Free Vulnerability. The bug is confined to SIP sessions handled by the connection-tracking helper and NAT SDP hooks. It requires SIP traffic traversing a host with nf_conntrack_sip (and relevant NAT) loaded. The integrity of signaling is compromised; remote attackers who can pass SDP through the helper can influence the rewritten addresses. The scope should be reviewed against whether IPv4/IPv6 SIP transit applies (network vs. strictly local control plane). #CVE-2026-31427 #SIP
Post summary
The tweet discloses a new Linux kernel use‑after‑free vulnerability (CVE-2026-31427) that impacts SIP sessions via the connection-tracking helper and NAT SDP hooks, providing concrete technical details but no evidence of exploitation or remediation.

