PT-2026-30150 · Linux+2 · Linux Kernel+2

CVE-2026-23455

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.10 through 6.19
Description An out-of-bounds read exists in the H.323 connection tracking parser within the netfilter module. The issue occurs in the DecodeQ931() function during the processing of Q.931 signaling messages. Specifically, in the UserUserIE code path, the system reads a 16-bit length from a packet and decrements it by 1 to skip the protocol discriminator byte before passing the value to the DecodeH323 UserInformation() function. If the encoded length is 0, the decrement causes the value to wrap to -1. This signed integer is then interpreted as a very large positive value by the decoder, leading to an unbounded read of kernel memory until an unmapped page or parse error is encountered. This can result in the disclosure of sensitive kernel memory, such as crypto keys, credentials, or pointers that could defeat KASLR (Kernel Address Space Layout Randomization), a security feature that randomizes the location of kernel code in memory to make exploitation harder.
Recommendations Update the Linux kernel to a version where the fix is applied for versions 5.10 through 6.19. As a temporary workaround, restrict access to UDP port 1719 and TCP port 1720 to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21556
ALSA-2026:21557
ALSA-2026:21706
ALSA-2026:21745
CVE-2026-23455
ECHO-0A50-5C88-4815
OESA-2026-2172
OESA-2026-2173
OESA-2026-2176
OPENSUSE-SU-2026:20826-1
RHSA-2026:21556
RHSA-2026:21557
RHSA-2026:21706
RHSA-2026:21745
RHSA-2026:25218
RHSA-2026:26462
RHSA-2026:26515
RHSA-2026:27713
RHSA-2026:33899
RHSA-2026:35844
SUSE-SU-2026:2068-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8493-1
USN-8493-2
USN-8497-1
USN-8498-1
USN-8499-1
USN-8501-1
USN-8508-1
USN-8527-1
USN-8528-1
USN-8529-1
USN-8530-1
USN-8545-1
USN-8546-1
USN-8547-1
USN-8548-1
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux