CVE 8.2 HIGH

netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case_CVE-2026-23456

8.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case

In decode_int(), the CONS case calls get_bits(bs, 2) to read a length
value, then calls get_uint(bs, len) without checking that len bytes
remain in the buffer. The existing boundary check only validates the
2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint()
reads. This allows a malformed H.323/RAS packet to cause a 1-4 byte
slab-out-of-bounds read.

Add a boundary check for len bytes after get_bits() and before
get_uint().

Basic Information

ID CVE-2026-23456
Source Linux
Published Apr 3, 2026 at 15:15
Modified Apr 27, 2026 at 14:02

Affected Product

Vendor Linux
Product Linux
Version 5e35941d990123f155b02d5663e51a24f816b6f3
Affected Versions Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 2.6.17

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.