Review reviewHigh

CVE-2026-23456

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checking that len bytes remain in the buffer. The existing boundary check only validates the 2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint() reads. This allows a malformed H.323/RAS packet to cause a 1-4 byte slab-out-of-bounds read. Add a boundary check for len bytes after get_bits() and before get_uint().

CVSS
8.2
EPSS
0.52%
41.5% percentile
CISA KEV
Not listed
Published
2026.04.04
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.52%
Technical severityCVSS 8.2

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checking that len bytes remain in the buffer. The existing boundary check only validates the 2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint() reads. This allows a malformed H.323/RAS packet to cause a 1-4 byte slab-out-of-bounds read. Add a boundary check for len bytes after get_bits() and before get_uint().

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= 5e35941d990123f155b02d5663e51a24f816b6f3 < a2cd54b9348e485d338b3c132338a4410c99afaf, >= 5e35941d990123f155b02d5663e51a24f816b6f3 < c95dc674ebf01ecfb40388b6facfc89b81fed3b7, >= 5e35941d990123f155b02d5663e51a24f816b6f3 < 41b417ff73a24b2c68134992cc44c88db27f482d, >= 5e35941d990123f155b02d5663e51a24f816b6f3 < 52235bf88159a1ef16434ab49e47e99c8a09ab20, >= 5e35941d990123f155b02d5663e51a24f816b6f3 < 774a434f8c9c8602a976b2536f65d0172a07f4d2, >= 5e35941d990123f155b02d5663e51a24f816b6f3 < 6bce72daeccca9aa1746e92d6c3d4784e71f2ebb, >= 5e35941d990123f155b02d5663e51a24f816b6f3 < fb6c3596823ec5dd09c2123340330d7448f51a59, >= 5e35941d990123f155b02d5663e51a24f816b6f3 < 1e3a3593162c96e8a8de48b1e14f60c3b57fca8a, >= 2.6.17, >= V3.1.6, >= V3.1.5, >= 2.6.17 < 5.10.253, >= 5.11 < 5.15.203, >= 5.16 < 6.1.167, >= 6.2 < 6.6.130, >= 6.7 < 6.12.78, >= 6.13 < 6.18.20, >= 6.19 < 6.19.10, 7.0
Fixed versions
5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CWE
CWE-125