Cryptographic Configuration Flaw in Kronosnet Software by KronosNet
CVE-2026-15811
5.8MEDIUM
What is CVE-2026-15811?
A security vulnerability exists in Kronosnet's cryptographic configuration management, where sensitive memory segments are not properly zeroed out after alterations. This oversight enables local attackers to potentially access unprotected encryption keys remaining in memory. By leveraging techniques to disclose memory content, malicious actors could exploit this flaw to decrypt secured cluster network communications, or insert harmful packets, which could lead to significant disruptions in high-availability cluster operations.
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Fabio Di Nitto for reporting this issue.