Impact
The vulnerability resides in the Linux kernel’s netfilter conntrack IRC helper, where a malformed command string can lead to an out‑of‑bounds read. The read occurs after a parsing failure, potentially exposing sensitive kernel memory contents. Based on the description, the likely attack vector is a malformed IRC packet delivered over the network to a host running the affected helper.
Affected Systems
All configurations of the Linux kernel that enable the netfilter conntrack IRC helper are potentially affected. No specific upstream kernel release or version range is indicated in the advisory.
Risk and Exploitability
No CVSS score or EPSS value is provided, and the vulnerability is not listed in CISA’s KEV catalog. The flaw can be triggered by a remote attacker sending a crafted IRC packet that causes a parsing failure, leading to an out‑of‑bounds read of kernel memory.
OpenCVE Enrichment