cbcvebase.
CVE-2026-23457
published 2026-04-03

CVE-2026-23457: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()…

PriorityP346high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
0.43%
35.5th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length header with simple_strtoul(), which returns unsigned long, but stores the result in unsigned int clen. On 64-bit systems, values exceeding UINT_MAX are silently truncated before computing the SIP message boundary. For example, Content-Length 4294967328 (2^32 + 32) is truncated to 32, causing the parser to miscalculate where the current message ends. The loop then treats trailing data in the TCP segment as a second SIP message and processes it through the SDP parser. Fix this by changing clen to unsigned long to match the return type of simple_strtoul(), and reject Content-Length values that exceed the remaining TCP payload length.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < ed81b6a7012485acdb9c6c80735a0b7d8e5e1873ed81b6a7012485acdb9c6c80735a0b7d8e5e1873
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < cd1b7403ec835f8a0b3f1f7e68ac26af2cb1e42fcd1b7403ec835f8a0b3f1f7e68ac26af2cb1e42f
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < b75209debb9adab287b3caa982f77788c1e15027b75209debb9adab287b3caa982f77788c1e15027
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < 528b4509c9dfc272e2e92d811915e5211650d383528b4509c9dfc272e2e92d811915e5211650d383
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < 75fcaee5170e7dbbee778927134ef2e9568b465975fcaee5170e7dbbee778927134ef2e9568b4659
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < 865dba58958c3a86786f89a501971ab0e3ec6ba9865dba58958c3a86786f89a501971ab0e3ec6ba9
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < d4f17256544cc37f6534a14a27a9dec3540c2015d4f17256544cc37f6534a14a27a9dec3540c2015
linuxlinux>= f5b321bd37fbec9188feb1f721ab46a5ac0b35da < fbce58e719a17aa215c724473fd5baaa4a8dc57cfbce58e719a17aa215c724473fd5baaa4a8dc57c
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 2.6.34 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
vendor_ubuntu7.1HIGH
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.