PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23455 Linux CVE debrief

An integer underflow vulnerability exists in the Linux kernel's netfilter H.323 connection tracking module. In the DecodeQ931() function, a 16-bit length field read from packet data is decremented by 1 to skip the protocol discriminator byte before being passed to DecodeH323_UserInformation(). When the encoded length is 0, this decrement wraps to -1 (interpreted as a large unsigned value), causing an out-of-bounds read. The vulnerability affects Linux kernel versions from 2.6.17 through multiple stable branches, with patches available for supported releases. This is a network-reachable vulnerability in connection tracking code processing H.323/Q.931 protocol data.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Linux system administrators, network security engineers, telecommunications infrastructure operators using H.323 protocols, kernel maintainers, and organizations running VoIP or video conferencing systems that rely on H.323 connection tracking.

Technical summary

The vulnerability resides in net/netfilter/nf_conntrack_h323_main.c in the DecodeQ931() function. When processing Q.931 User-User Information Elements (IE), the code reads a 16-bit length field and decrements it by 1 to account for the protocol discriminator byte. The absence of a check for zero length before this decrement causes an integer underflow, resulting in a very large length value being passed to the ASN.1 decoder (DecodeH323_UserInformation()). This leads to out-of-bounds memory access when the decoder attempts to read beyond packet boundaries. The fix adds a validation check to ensure the length remains positive after decrement.

Defensive priority

critical

Recommended defensive actions

  • Apply kernel patches from stable branches: 5.10.253+, 5.15.203+, 6.1.167+, 6.6.130+, 6.12.78+, 6.18.20+, 6.19.10+, or 7.0-rc5+
  • If patching is not immediately feasible, consider disabling H.323 connection tracking helper (nf_conntrack_h323) if not required for operations
  • Monitor for kernel updates from distribution maintainers for backported fixes
  • Review network segmentation to limit exposure of H.323 services where possible
  • Validate that security monitoring can detect anomalous H.323/Q.931 traffic patterns

Evidence notes

Vulnerability description sourced from NVD CVE record published 2026-04-03 and modified 2026-05-26. Root cause confirmed by kernel patch commits adding length validation check. CWE-125 (Out-of-bounds Read) assigned by NVD. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H indicates network attack vector with low complexity, no privileges required, and high impact to confidentiality and availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23455 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23455

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23455 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23455

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2121f5fbe88daff0f1fc5bc47d359426c74b86b0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/495e97af9e7249ee02b72bb1d0848a6efc3700f4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/633e8f87dad32263f6a57dccdb873f042c062111

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/65fa92f79677858b14b9e4b7275f26639afe2710

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9d00fe7d6d7c5b5f1065a6e042b54f2e44bd6df8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b652b05d51003ac074b912684f9ec7486231717b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f173d0f4c0f689173f8cdac79991043a4a89bf66

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.