Access Control List Vulnerability in kronosnet by Red Hat
CVE-2026-15812

4.8MEDIUM

What is CVE-2026-15812?

A critical vulnerability exists in the internal Access Control List (ACL) subsystem of kronosnet, specifically in versions 1.34 and below. When the system is configured to manage dynamic links and accepts incoming network traffic from any IP address without encrypting the payload, it inadvertently trusts the link ID in the incoming data packets. This lack of adequate validation allows a remote, unauthenticated attacker to spoof legitimate link IDs in crafted network frames, enabling them to bypass the ACL framework entirely. Consequently, the attacker can inject arbitrary data packets into the application layer, resulting in potential data corruption or instability of services.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Fabio Di Nitto for reporting this issue.
.