Out-of-bounds read in Linux kernel - CVE-2026-98077
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in sip_skip_whitespace() in nf_conntrack_sip when processing a SIP payload containing a recognized header name followed by whitespace at the end of the payload. A remote attacker can send such a crafted SIP payload to trigger an out-of-bounds read.