8.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case
In decode_int(), the CONS case calls get_bits(bs, 2) to read a length
value, then calls get_uint(bs, len) without checking that len bytes
remain in the buffer. The existing boundary check only validates the
2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint()
reads. This allows a malformed H.323/RAS packet to cause a 1-4 byte
slab-out-of-bounds read.
Add a boundary check for len bytes after get_bits() and before
get_uint().
netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case
In decode_int(), the CONS case calls get_bits(bs, 2) to read a length
value, then calls get_uint(bs, len) without checking that len bytes
remain in the buffer. The existing boundary check only validates the
2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint()
reads. This allows a malformed H.323/RAS packet to cause a 1-4 byte
slab-out-of-bounds read.
Add a boundary check for len bytes after get_bits() and before
get_uint().
Basic Information
ID
CVE-2026-23456
Source
Linux
Published
Apr 3, 2026 at 15:15
Modified
Apr 27, 2026 at 14:02
Affected Product
Vendor
Linux
Product
Linux
Version
5e35941d990123f155b02d5663e51a24f816b6f3
Affected Versions
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 2.6.17
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 5e35941d990123f155b02d5663e51a24f816b6f3
Linux Linux 2.6.17
References
- git.kernel.org /stable/c/a2cd54b9348e485d338b3c132338a4410c99afaf
- git.kernel.org /stable/c/c95dc674ebf01ecfb40388b6facfc89b81fed3b7
- git.kernel.org /stable/c/41b417ff73a24b2c68134992cc44c88db27f482d
- git.kernel.org /stable/c/52235bf88159a1ef16434ab49e47e99c8a09ab20
- git.kernel.org /stable/c/774a434f8c9c8602a976b2536f65d0172a07f4d2
- git.kernel.org /stable/c/6bce72daeccca9aa1746e92d6c3d4784e71f2ebb
- git.kernel.org /stable/c/fb6c3596823ec5dd09c2123340330d7448f51a59
- git.kernel.org /stable/c/1e3a3593162c96e8a8de48b1e14f60c3b57fca8a