CVE-2026-45843 Details
Description
In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neither helper bounds-checks against isize, and decode() masks its return with & 0xffff so it can never return the -1 that callers test for -- those error paths are dead code. A short compressed frame whose change byte requests optional fields lets decode() read past the end of the packet. The over-read bytes are folded into the cached cstate and reflected into subsequent reconstructed packets. Make decode() and pull16() take the packet end pointer and return -1 when exhausted. Add a bounds check before the TCP-checksum read. The existing == -1 tests now do what they were always meant to.
A vulnerability in the Linux kernel's handling of VJ-compressed TCP headers can lead to out-of-bounds reading. The issue arises in the SLIP (Serial Line Internet Protocol) compression driver, specifically within the 'slhc_uncompress()' function. This function processes compressed TCP headers by moving a pointer through the packet using the 'decode()' and 'pull16()' functions. However, these functions do not properly check the packet size, allowing 'decode()' to read beyond the packet's end. The over-read data is then incorporated into the internal state and affects subsequent packets. The vulnerability can be exploited by sending a short compressed frame that requests optional fields, causing 'decode()' to over-read and potentially expose sensitive data.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. The commit addressing this issue is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0511ecb00e61bf28e2fec4bb41fcce385c3a3b2d | kernel.org | Patch |
| https://git.kernel.org/stable/c/335957df4ed60f02a2ec0432fbedbf0cc7241d8b | kernel.org | Patch |
| https://git.kernel.org/stable/c/37537e42e6df387398bee85cb85070cc80bb1e10 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4c1367a2d7aad643a6f87c6931b13cc1a25e8ca7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4cefe32639933d652614b0bd50f818f9af4af78f | kernel.org | Patch |
| https://git.kernel.org/stable/c/6268f01ae989013671b526c883e92655342c6f6f | kernel.org | Patch |
| https://git.kernel.org/stable/c/9aafba2f49e1fcccc2018816f5836a609c925879 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d42bec6e4f6d6d658be365539400b3314b76b2a7 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.12.1, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 30, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |