Junglewise Threat Intelligence

CVE-2026-53268: Linux Kernel out-of-bounds read in netfilter conntrack_irc

CVE-2026-53268 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's IRC connection tracking component, which is used by firewalls to manage Internet Relay Chat traffic. An attacker could potentially trigger an out-of-bounds memory read by sending specially crafted IRC commands. This could lead to system instability or the exposure of sensitive kernel memory information.

Technical details

An out-of-bounds read vulnerability exists in net/netfilter/nf_conntrack_irc.c within the Linux kernel. The issue occurs in the help() function when parsing DCC (Direct Client-to-Client) commands; if parsing fails after a command string has been matched, the code incorrectly continues to attempt matching other commands instead of bailing out. This logic error can result in an out-of-bounds read from kernel memory. The vulnerability is reachable over the network if the IRC conntrack helper is enabled. Patches have been released across multiple stable kernel branches to replace the 'continue' statements with 'goto out' to properly terminate parsing on failure.

Affected products

  • Linux Linux Kernel 2.6.20 to 6.1.176, 6.6.143, 5.10.259, 5.15.210

Timeline

  • 2026-05-27: patched: Initial patch authored by Florian Westphal
  • 2026-06-25: advisory: CVE-2026-53268 published by NVD

References

Related threats