In the Linux kernel, the following vulnerability has been...
Critical severity
Unreviewed
Published
Apr 6, 2026
to the GitHub Advisory Database
•
Updated May 20, 2026
Description
Published by the National Vulnerability Database
Apr 6, 2026
Published to the GitHub Advisory Database
Apr 6, 2026
Last updated
May 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-net: fix OOB access in ULE extension header tables
The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables
in handle_one_ule_extension() are declared with 255 elements (valid
indices 0-254), but the index htype is derived from network-controlled
data as (ule_sndu_type & 0x00FF), giving a range of 0-255. When
htype equals 255, an out-of-bounds read occurs on the function pointer
table, and the OOB value may be called as a function pointer.
Add a bounds check on htype against the array size before either table
is accessed. Out-of-range values now cause the SNDU to be discarded.
References