CVE-2026-23455

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/04/2026
Last modified:
03/04/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()<br /> <br /> In DecodeQ931(), the UserUserIE code path reads a 16-bit length from<br /> the packet, then decrements it by 1 to skip the protocol discriminator<br /> byte before passing it to DecodeH323_UserInformation(). If the encoded<br /> length is 0, the decrement wraps to -1, which is then passed as a<br /> large value to the decoder, leading to an out-of-bounds read.<br /> <br /> Add a check to ensure len is positive after the decrement.

Impact