CVE-2026-23456Patch(linux / linux_kernel)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checking that len bytes remain in the buffer. The existing boundary check only validates the 2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint() reads. This allows a malformed H.323/RAS packet to cause a 1-4 byte slab-out-of-bounds read. Add a boundary check for len bytes after get_bits() and before get_uint().

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-01); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-03: 1Mentions · 2026-04-26: 1Mentions · 2026-06-01: 2Mentions · 2026-06-02: 1PoC Mentioned / Linked · 2026-06-01: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-06-01: 2Technical Details · 2026-04-03: 1Technical Details · 2026-04-26: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-02: 104-0304-2606-0106-02
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-031
Patch1
2026-04-261
Patch1
2026-06-012
Patch2
2026-06-021
Disclosure1
Full discourse5 posts
  • Jenny Qu@GuanniQu
    Patch

    found a remotely triggerable out-of-bounds read in the Linux kernel's H.323 connection tracking parser (CVE-2026-23456, CVSS 8.2). no authentication. no privileges. no user interaction. send a malformed packet to port 1720 on any Linux firewall or NAT gateway running nf_conntrack_h323 and you're reading kernel slab memory. some context on why this matters more than a typical kernel OOB. H.323 is a VoIP signaling protocol from the 1990s. it is everywhere you don't think to look. telecom carriers, enterprise PBXs, session border controllers, hospital phone systems, building intercoms, elevator emergency phones, legacy videoconferencing. every Linux-based firewall or NAT device that needs to track H.323 connections for dynamic port allocation loads nf_conntrack_h323, which contains a full ASN.1 PER decoder running inline in the kernel, parsing untrusted data from the network, at wire speed, with direct access to kernel memory. this module auto-loads when H.323 traffic hits a conntrack rule. on many distributions it's loaded by default. the attack surface is: send a packet from the internet to a machine that might be doing NAT for a phone system somewhere behind it. the bug. in decode_int(), the CONS case: nf_h323_error_boundary(bs, 0, 2) len = get_bits(bs, 2) + 1 BYTE_ALIGN(bs) v = get_uint(bs, len) the boundary check validates 2 bits for get_bits(). it does not validate len bytes for get_uint(). the length field is bounds-checked. the data described by the length field is not. craft a H.323/RAS packet where the bitstream is truncated after the length field. get_uint() walks 1–4 bytes off the end of a slab allocation. the attacker controls which allocation this is and can potentially influence what's adjacent in the slab cache. 1–4 bytes doesn't sound like much until you remember that kernel pointers, ASLR secrets, and crypto material all live in slab memory and a single leaked pointer can defeat KASLR. now the interesting part. after the patch landed, Jakub Kicinski's AI code reviewer flagged five other locations in the same file as having the same bug: UNCO in decode_int, SEMI in decode_bitstr, SEMI and default in decode_octstr, BYTE in decode_bmpstr. all five advance bs->cur without checking that enough bytes remain. Florian went through each one and found a post-advance boundary check after every single one. "this LLM response is bunk." he was right. but the reason he was right is the reason the CONS case is a real bug and the other five are not, and I think this is where current AI code review genuinely cannot tell the difference. the other cases do this: advance bs->cur past the data without dereferencing, then check nf_h323_error_boundary(bs, 0, 0) after the switch block. the pointer overshoots. nothing reads through it. the boundary check fires. the function returns an error. pointer arithmetic past the end of a buffer is not a memory safety violation, only pointer dereference is. the pointer moved into illegal territory but nobody looked through the window. the CONS case is different. get_uint(bs, len) dereferences *bs->cur++ inline. it reads 1–4 bytes from memory as part of advancing. the dereference and the advance are the same operation. there is no "temporary overshoot" because the bytes are physically read from memory during the overshoot. a post-advance boundary check cannot un-read memory. the AI saw "pointer advances without pre-check" six times and pattern-matched all of them as the same bug. five of them advance a pointer. one of them reads through a pointer while advancing. pointer arithmetic vs pointer dereference is the entire vulnerability, and current AI review can't see the difference because it's matching on control flow shape, not on what the CPU actually does when the instruction executes. the fix is two lines. one call to nf_h323_error_boundary(bs, len, 0) between get_bits() and get_uint(). the original commit is 5e35941d9901, "[NETFILTER]: Add H.323 conntrack/NAT helper", from 2007. twenty years of a full ASN.1 decoder running in kernel space, parsing untrusted packets from the network, with a missing bounds check on a length-prefixed read. loaded by default on most distributions. reachable without authentication. the fix is two lines. reported by Klaudia Kloc and Dawid Moczadło from @VidocSecurity. I verified the bug, wrote the PoC, and submitted the patch. patched in stable 5.10–6.19.

    Post summary

    A remotely triggerable out‑of‑bounds read was discovered in Linux kernel’s H.323 conntrack parser (CVE‑2026‑23456), a PoC was developed, and a two‑line patch was released for kernels 5.10‑6.19.

    42321286317.1K
    2.2K followersView on X
  • Jenny Qu@GuanniQu
    Patch

    CVE-2026-23456 | CVSS 8.2 patch: https://lore.kernel.org/netfilter-devel/20260313150614.21177-7-fw@strlen.de/AI review thread: https://lore.kernel.org/netfilter-devel/CAFzOa16enGosPApaXYmypkUb8JK=SMsvi2XMSrDP+DShm=GMLQ@mail.gmail.com/ mainline: https://github.com/torvalds/linux/commit/1e3a3593162c96e8a8de48b1e14f60c3b57fca8a buggy commit: https://github.com/torvalds/linux/commit/5e35941d9901 originally reported by @VidocSecurity (Klaudia Kloc and Dawid Moczadło). I confirmed, reproduced, and patched it.

    Post summary

    The CVE-2026-23456 issue has been addressed with a Linux kernel patch, as evidenced by the provided commit URLs.

    310931.7K
    2.2K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    No auth. No privileges. No interaction. Just a malformed packet. CVE-2026-23456 - CVSS 8.2 - remotely triggerable out-of-bounds read in the Linux kernel's H.323 connection tracking parser. Send one packet to port 1720. Crash your target's Linux firewall or NAT gateway. Every Linux network perimeter is in scope. http://VulnTracker.io

    Post summary

    The tweet announces a new CVE-2026-23456 affecting the Linux kernel, detailing an out‑of‑bounds read via a malformed packet to port 1720 with a CVSS score of 8.2, and signals that all Linux network perimeter devices are affected.

    01000243
    660 followersView on X
  • Cyber Netsec IO@NetSecIO
    Patch

    🚨 A Log4j-style crisis averted! A critical 10.0 CVSS RCE flaw, CVE-2026-23456, was found in the popular 'LogSpresso' Java library. 😱 Patch released before wild exploitation. Update to version 3.5.1 NOW! #LogSpresso #Vulnerability #SupplyChain #Java https://t.co/n5FDzkY9zQ

    Post summary

    The tweet announces a critical RCE vulnerability in LogSpresso (CVE‑2026‑23456) and urges users to apply the published patch (v3.5.1) immediately.

    0000072
    44 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23456 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS c… https://www.cve.org/CVERecord?id=CVE-2026-23456

    Post summary

    The text announces that CVE-2026-23456, an out-of-bounds read in the Netfilter nf_conntrack_h323 module, has been fixed in the Linux kernel, with no exploitation or PoC information provided.

    0000094
    56.9K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more