PT-2026-30150 · Linux+3 · Linux Kernel+3

CVE-2026-23455

·

Published

2026-03-13

·

Updated

2026-08-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.10 through 6.19
Description An out-of-bounds read exists in the H.323 connection tracking parser within the netfilter module. The issue occurs in the DecodeQ931() function during the processing of the UserUserIE code path. The function reads a 16-bit length from a packet and decrements it by 1 to skip the protocol discriminator byte before passing the result to the DecodeH323 UserInformation() function. If the encoded length is 0, the decrement causes the value to wrap to -1. Because this value is interpreted as a large positive integer by the decoder, the kernel may read memory far beyond the packet buffer until it encounters an unmapped page. This can lead to unbounded kernel memory disclosure, potentially exposing kernel pointers, cryptographic keys, or credentials from other processes. The flaw is remotely triggerable via UDP port 1719 or TCP port 1720 without authentication or privileges.
Recommendations Update the Linux kernel to a version where the fix has been applied for versions 5.10 through 6.19. As a temporary mitigation, restrict network access to UDP port 1719 and TCP port 1720 to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21556
ALSA-2026:21557
ALSA-2026:21706
ALSA-2026:21745
BDU:2026-12238
CVE-2026-23455
ECHO-0A50-5C88-4815
LSN-0121-1
OESA-2026-2172
OESA-2026-2173
OESA-2026-2176
OPENSUSE-SU-2026:20826-1
RHSA-2026:21556
RHSA-2026:21557
RHSA-2026:21706
RHSA-2026:21745
RHSA-2026:25218
RHSA-2026:26462
RHSA-2026:26515
RHSA-2026:27713
RHSA-2026:33899
RHSA-2026:35844
RHSA-2026:35863
RHSA-2026:35896
RHSA-2026:41236
SUSE-SU-2026:2068-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8493-1
USN-8493-2
USN-8497-1
USN-8498-1
USN-8499-1
USN-8501-1
USN-8508-1
USN-8527-1
USN-8528-1
USN-8529-1
USN-8529-2
USN-8530-1
USN-8530-2
USN-8545-1
USN-8546-1
USN-8547-1
USN-8547-2
USN-8548-1
USN-8548-2
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8615-1
USN-8615-2
USN-8616-1
USN-8617-1
USN-8619-1
USN-8635-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu