Cryptographic Configuration Flaw in Kronosnet Software by KronosNet
CVE-2026-15811

5.8MEDIUM

What is CVE-2026-15811?

A security vulnerability exists in Kronosnet's cryptographic configuration management, where sensitive memory segments are not properly zeroed out after alterations. This oversight enables local attackers to potentially access unprotected encryption keys remaining in memory. By leveraging techniques to disclose memory content, malicious actors could exploit this flaw to decrypt secured cluster network communications, or insert harmful packets, which could lead to significant disruptions in high-availability cluster operations.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Fabio Di Nitto for reporting this issue.
.