🔴 严重 | CVE-2026-53002 — In the Linux kernel, the following vulnerability has be
🔴 《严重安全漏洞:CVE-2026-53002》
CVSS 评分: 严重(9.8) CVE ID: CVE-2026-53002
漏洞描述
In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack: remove sprintf usage
Replace it with scnprintf, the buffer sizes are expected to be large enough
to hold the result, no need for snprintf+overflow check.
Increase buffer size in mangle_content_len() while at it.
BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270
Write of size 1 at addr [..]
vsnprintf+0xea5/0x1270
sprintf+0xb1/0xe0
mangle_content_len+0x1ac/0x280
nf_nat_sdp_session+0x1cc/0x240
process_sdp+0x8f8/0xb80
process_invite_request+0x108/0x2b0
process_sip_msg+0x5da/0xf50
sip_help_tcp+0x45e/0x780
nf_confirm+0x34d/0x990
[..]
| 字段 | 值 |
|---|---|
| CVE ID | CVE-2026-53002 |
| CVSS 评分 | 9.8 |
| 严重程度 | 严重 |
| 发布时间 | 2026-06-24 |
| 状态 | Received |
数据来源: NVD | 获取时间: 2026-06-28 18:14
💬 评论