Out-of-bounds read in Linux kernel - CVE-2026-74569
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in ct_sip_get_header() in the nf_conntrack_sip SIP connection-tracking helper when processing NAT-rewritten SIP messages over TCP. A remote attacker can send a specially crafted SIP message with a long Contact list to cause a denial of service.
The issue is triggered by integer wraparound in size-change tracking during repeated URI rewriting, which can produce an invalid length value for a subsequent header parse.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74569
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/63eea41759fd682229c14e0a2205802b46d106f3
- https://git.kernel.org/stable/c/c97621a110e386b2dd69e276eb699e1d3cec581d
- https://git.kernel.org/stable/c/db3d0e0e5d4bc5ab4fe445b9f413d1b486508ca5
- https://git.kernel.org/stable/c/ef5e2c6555d2bb52dfe0e4053a8c6193f9d83b64
- https://git.kernel.org/stable/c/f74554e67ccf04d1fa71069e8c9afa2717e40716