A flaw tracked as CVE-2026-23455 was disclosed in the Linux kernel's netfilter subsystem, affecting the nf_conntrack_h323 module used for H.323 connection tracking. In the DecodeQ931() path, a zero-length value can trigger an integer underflow and wraparound, leading to an out-of-bounds read in net/netfilter/nf_conntrack_h323_asn1.c. The bug can cause denial of service and may expose sensitive information; Red Hat rated it Moderate with a CVSS v3 score of 7.1, while cve.org published a higher 9.1 vector based on different exploitability assumptions.
The Linux kernel CVE team said the vulnerable code dates back to kernel 2.6.17 and reported fixes in multiple upstream stable branches, including 6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10, and 7.0-rc5. Red Hat later shipped remediation through security errata for several Red Hat Enterprise Linux releases and included the flaw in RHSA-2026:35844, an Important kernel update for RHEL 7 Extended Lifecycle Support on x86_64, s390x, ppc64, and ppc64le; the advisory updates systems to kernel 3.10.0-1160.154.1.el7 and requires a reboot after installation.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:35844, an Important kernel security advisory for Red Hat Enterprise Linux 7 Extended Lifecycle Support, fixing CVE-2026-23455 along with three other kernel vulnerabilities. The advisory updated the kernel to version 3.10.0-1160.154.1.el7 and required a reboot after installation.
Red Hat released security errata fixing CVE-2026-23455 for RHEL 10 and RHEL 8 kernel packages, including RHSA-2026:21557, RHSA-2026:21745, and RHSA-2026:21706. These advisories addressed the nf_conntrack_h323 zero-length handling flaw in affected kernel builds.
Red Hat published its CVE entry for CVE-2026-23455, describing the Linux kernel netfilter nf_conntrack_h323 flaw as a Moderate-severity out-of-bounds read that could cause denial of service or disclose sensitive information. Red Hat assigned the issue a CVSS v3 score of 7.1.
The Linux kernel CVE team assigned CVE-2026-23455 to the nf_conntrack_h323 DecodeQ931() out-of-bounds read vulnerability. The announcement also identified fixes across multiple stable and release candidate kernel branches.
The Linux kernel CVE announcement states the out-of-bounds read flaw in netfilter's nf_conntrack_h323 component was introduced in Linux kernel 2.6.17. The bug stems from DecodeQ931() decrementing a zero length value and passing the wrapped result onward.
Red Hat released RHSA-2026:55445 to fix CVE-2026-23455 in Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages. This extended the fix to the RHEL 10.0 EUS stream.
Red Hat released RHSA-2026:41236 to fix CVE-2026-23455 in Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel-rt packages. This added remediation for the real-time kernel variant.
Red Hat released RHSA-2026:35896 to fix CVE-2026-23455 in RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages. The erratum extended coverage to affected 8.4 streams.
Red Hat released RHSA-2026:33899 to fix CVE-2026-23455 in RHEL 8.6 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages. The advisory covered affected 8.6 update streams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.