-
CVE-2026-98077
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:24:15
- Zuletzt bearbeitet 03.10.2026 11:18:29
- Erkennungen
netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
sip_skip_whitespace() returns dptr unchanged when its own loop
exhausts the buffer (dptr == limit), instead of NULL like its sibling
sip_follow_continuation() returns on its own "no more data" path.
ct_sip_get_header() only checks for NULL after calling it:
dptr = sip_skip_whitespace(dptr, limit);
if (dptr == NULL)
break;
if (*dptr != ':' || ++dptr >= limit)
break;
so a recognized header name followed only by spaces/tabs running to
the exact end of the SIP payload, with no colon, makes the very next
statement read one byte past the buffer.
Make both "no more data" outcomes return NULL, matching the
convention sip_follow_continuation() already uses and that both
existing callers already check for.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
9ae0a87e6f513293677fe286729fbae34d592215
Status
affected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
b6277622b7323000895b674321c9a1f060553188
Status
affected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
0cfb96a118c5c6d46d7a1cfdfa18355ad734ca79
Status
affected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
c6beb08b1a9fdb96795816d8329ed75dd785d48e
Status
affected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
60c012b2d05e1558b0f30ea3f15a2c3ca2f24d94
Status
affected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
4be8380e3af008f418f97992c06f23be649a430d
Status
affected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
4a30aa2ba007db18210dd52219ecbd5528c03523
Status
affected
Version
ea45f12a2766dae54e5426a23e8f4bafdbe2782e
Version <
e8f8231824b5815f57ce62cba116e511b10196de
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.26
Status
affected
Version
0
Version <
2.6.26
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.089 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/60c012b2d05e1558b0f30ea3f15a2c3ca2f24d94
https://git.kernel.org/stable/c/4be8380e3af008f418f97992c06f23be649a430d
https://git.kernel.org/stable/c/4a30aa2ba007db18210dd52219ecbd5528c03523
https://git.kernel.org/stable/c/e8f8231824b5815f57ce62cba116e511b10196de
https://git.kernel.org/stable/c/0cfb96a118c5c6d46d7a1cfdfa18355ad734ca79
https://git.kernel.org/stable/c/9ae0a87e6f513293677fe286729fbae34d592215
https://git.kernel.org/stable/c/b6277622b7323000895b674321c9a1f060553188
https://git.kernel.org/stable/c/c6beb08b1a9fdb96795816d8329ed75dd785d48e