VDB

DEBIAN-CVE-2026-23455

DEBIAN-CVE-2026-23455 PUBLISHED CVSS 9.100000381469727 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing it to DecodeH323_UserInformation(). If the encoded length is 0, the decrement wraps to -1, which is then passed as a large value to the decoder, leading to an out-of-bounds read. Add a check to ensure len is positive after the decrement.

Risk Scores

CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected Products

VendorProductVersions
Debian:14linux6.12.38-1, 6.12.43-1, 6.12.43-1~bpo12+1
Debian:12linux0, 6.1.106-2, 6.1.106-3
Debian:11linux-6.16.1.164-1, 6.1.162-1, 6.1.159-1
Debian:11linux6.15, 6.9.7-1, 6.9.8-1
Debian:13linux6.12.43-1, 6.12.43-1, 6.12.48-1

Timeline

  • Apr 3, 2026 CVE Published
  • May 2, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›