Network Packet De-fragmentation Vulnerability in kronosnet by Red Hat
CVE-2026-15813

6.5MEDIUM

What is CVE-2026-15813?

A security flaw exists in the network packet de-fragmentation engine of kronosnet, where the internal reassembly code fails to validate sequence numbers of incoming payload fragments. This vulnerability allows an attacker to exploit the system by sending malformed packets with corrupted sequence information. If triggered, it can lead to out-of-bounds memory access or heap corruption, resulting in unexpected application crashes or overall system instability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Fabio Di Nitto for reporting this issue.
.