In the Linux kernel, the following vulnerability has been...
Critical severity
Unreviewed
Published
Apr 3, 2026
to the GitHub Advisory Database
•
Updated May 26, 2026
Description
Published by the National Vulnerability Database
Apr 3, 2026
Published to the GitHub Advisory Database
Apr 3, 2026
Last updated
May 26, 2026
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
In DecodeQ931(), the UserUserIE code path reads a 16-bit length from
the packet, then decrements it by 1 to skip the protocol discriminator
byte before passing it to DecodeH323_UserInformation(). If the encoded
length is 0, the decrement wraps to -1, which is then passed as a
large value to the decoder, leading to an out-of-bounds read.
Add a check to ensure len is positive after the decrement.
References