SB2026040673 - Out-of-bounds read in Linux kernel netfilter
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-23456)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in decode_int() in nf_conntrack_h323 when parsing malformed H.323/RAS packets. A remote attacker can send a specially crafted packet to disclose sensitive information.
The issue can result in a 1-4 byte slab out-of-bounds read.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1e3a3593162c96e8a8de48b1e14f60c3b57fca8a
- https://git.kernel.org/stable/c/41b417ff73a24b2c68134992cc44c88db27f482d
- https://git.kernel.org/stable/c/52235bf88159a1ef16434ab49e47e99c8a09ab20
- https://git.kernel.org/stable/c/6bce72daeccca9aa1746e92d6c3d4784e71f2ebb
- https://git.kernel.org/stable/c/774a434f8c9c8602a976b2536f65d0172a07f4d2
- https://git.kernel.org/stable/c/fb6c3596823ec5dd09c2123340330d7448f51a59