Red Hat Enterprise Linux 10: out-of-bounds write
Medium6.5CVE-2026-15813 · Published Jul 20, 2026 · updated Aug 21, 2026
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-787
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 20 | Red Hat libcupsfilters: denial of service | High7.5 | No fix yet |
| Jul 20 | Red Hat Enterprise Linux 10: stack buffer overflow | Medium6.5 | No fix yet |
| Jul 20 | Red Hat: path traversal | Critical9.0 | No fix yet |
| Jul 20 | Red Hat Enterprise Linux 10: race condition | High7.3 | No fix yet |
| Jul 20 | Red Hat claircore: denial of service | Medium4.3 | No fix yet |
| Jul 20 | Red Hat: denial of service | Medium5.3 | No fix yet |