Integer Underflow Vulnerability in Wazuh Platform
CVE-2026-44251
6.5MEDIUM
What is CVE-2026-44251?
Wazuh, an open source security platform, suffers from an integer underflow vulnerability in version 3.0.0 and later, prior to 4.14.5. This flaw resides in the os_crypto/shared/msgs.c:389 code and enables enrolled Wazuh agents to crash the wazuh-remoted process on the manager. This leads to the immediate disconnection of all agents from the manager. Additionally, this underflow could be exploited via a second code path, potentially resulting in heap memory corruption. The issue has been rectified in version 4.14.5.
Affected Version(s)
wazuh >= 3.0.0, < 4.14.5
