SB20260828188 - Out-of-bounds read in Linux kernel netfilter
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80603)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect connection tracking state.
The vulnerability exists due to an out-of-bounds read in the parse_dcc() function in nf_conntrack_irc when parsing DCC command data without a newline present. A remote attacker can send specially crafted IRC DCC command data to cause incorrect connection tracking state.
The stray read may consume an uninitialized or stale byte, which can lead to an incorrect DCC IP address or port being recorded in the conntrack expectation.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2393f0bd7a467ad475598f3a5b9de27ca36e3037
- https://git.kernel.org/stable/c/2b70f61f569bb29acb380e6f616a1bbdee15668f
- https://git.kernel.org/stable/c/437e0a3854b3a44ec15afa9ab88ec215adf3a2fd
- https://git.kernel.org/stable/c/910c33e4a8c046c3cc1fa5a465a4d41a1bb398f1
- https://git.kernel.org/stable/c/abb8c32b88ea3f46beb68c34fe9a3ac8ed664e7e
- https://git.kernel.org/stable/c/aff589556ed772cb1c0c2d7b4d91ec45c0c39416
- https://git.kernel.org/stable/c/eeef3b81f449560653662df2dde6f6fe247c5365
- https://git.kernel.org/stable/c/ef6400ca25a13fd6dedbe8ef4a1d0979bbbfe88a