CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-23455

Critical · CVSS 9.1

Linux Kernel — Out-of-bounds read (CWE-125) via integer underflow in netfilter H.323 connection tracking

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-125

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing it to DecodeH323_UserInformation(). If the encoded length is 0, the decrement wraps to -1, which is then passed as a large value to the decoder, leading to an out-of-bounds read. Add a check to ensure len is positive after the decrement.

Search profile — drives PoC discovery

Symbols DecodeQ931DecodeH323_UserInformationnf_conntrack_h323UserUserIEnf_conntrack_h323_mainDecodeH323_UU_PDU
Keywords CVE-2026-23455nf_conntrack_h323DecodeQ931zero lengthout-of-bounds readnetfilter H323Linux kernel netfilterUserUserIE integer underflowDecodeH323_UserInformation
Versions: Linux kernel versions prior to fixes in commits: 2121f5fbe88d, 495e97af9e72, 633e8f87dad3, 65fa92f79677, 9d00fe7d6d7c

Affected packages

Linux Kernel 2.6.17 → 5.10.253
Linux Kernel 5.11.0 → 5.15.203
Linux Kernel 5.16.0 → 6.1.167
Linux Kernel 6.13.0 → 6.18.20
Linux Kernel 6.19.0 → 6.19.10
Linux Kernel 6.2.0 → 6.6.130
Linux Kernel 6.7.0 → 6.12.78

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z