PatchSiren cyber security CVE debrief
CVE-2026-23455 Linux CVE debrief
An integer underflow vulnerability exists in the Linux kernel's netfilter H.323 connection tracking module. In the DecodeQ931() function, a 16-bit length field read from packet data is decremented by 1 to skip the protocol discriminator byte before being passed to DecodeH323_UserInformation(). When the encoded length is 0, this decrement wraps to -1 (interpreted as a large unsigned value), causing an out-of-bounds read. The vulnerability affects Linux kernel versions from 2.6.17 through multiple stable branches, with patches available for supported releases. This is a network-reachable vulnerability in connection tracking code processing H.323/Q.931 protocol data.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Linux system administrators, network security engineers, telecommunications infrastructure operators using H.323 protocols, kernel maintainers, and organizations running VoIP or video conferencing systems that rely on H.323 connection tracking.
Technical summary
The vulnerability resides in net/netfilter/nf_conntrack_h323_main.c in the DecodeQ931() function. When processing Q.931 User-User Information Elements (IE), the code reads a 16-bit length field and decrements it by 1 to account for the protocol discriminator byte. The absence of a check for zero length before this decrement causes an integer underflow, resulting in a very large length value being passed to the ASN.1 decoder (DecodeH323_UserInformation()). This leads to out-of-bounds memory access when the decoder attempts to read beyond packet boundaries. The fix adds a validation check to ensure the length remains positive after decrement.
Defensive priority
critical
Recommended defensive actions
- Apply kernel patches from stable branches: 5.10.253+, 5.15.203+, 6.1.167+, 6.6.130+, 6.12.78+, 6.18.20+, 6.19.10+, or 7.0-rc5+
- If patching is not immediately feasible, consider disabling H.323 connection tracking helper (nf_conntrack_h323) if not required for operations
- Monitor for kernel updates from distribution maintainers for backported fixes
- Review network segmentation to limit exposure of H.323 services where possible
- Validate that security monitoring can detect anomalous H.323/Q.931 traffic patterns
Evidence notes
Vulnerability description sourced from NVD CVE record published 2026-04-03 and modified 2026-05-26. Root cause confirmed by kernel patch commits adding length validation check. CWE-125 (Out-of-bounds Read) assigned by NVD. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H indicates network attack vector with low complexity, no privileges required, and high impact to confidentiality and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23455 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23455
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23455 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23455
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2121f5fbe88daff0f1fc5bc47d359426c74b86b0
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/495e97af9e7249ee02b72bb1d0848a6efc3700f4
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/633e8f87dad32263f6a57dccdb873f042c062111
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/65fa92f79677858b14b9e4b7275f26639afe2710
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9d00fe7d6d7c5b5f1065a6e042b54f2e44bd6df8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b652b05d51003ac074b912684f9ec7486231717b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f173d0f4c0f689173f8cdac79991043a4a89bf66
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.