CVE 9.1 CRITICAL

netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()_CVE-2026-23455

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()

In DecodeQ931(), the UserUserIE code path reads a 16-bit length from
the packet, then decrements it by 1 to skip the protocol discriminator
byte before passing it to DecodeH323_UserInformation(). If the encoded
length is 0, the decrement wraps to -1, which is then passed as a
large value to the decoder, leading to an out-of-bounds read.

Add a check to ensure len is positive after the decrement.

Basic Information

ID CVE-2026-23455
Source Linux
Published Apr 3, 2026 at 15:15
Modified Apr 27, 2026 at 14:02

Affected Product

Vendor Linux
Product Linux
Version 5e35941d990123f155b02d5663e51a24f816b6f3
Affected Versions Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 2.6.17

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.