Unbounded Memory Allocation Vulnerability in Sonic 3 A.I.R. by Eukaryot
CVE-2026-66733

8.7HIGH

Key Information:

Vendor

Eukaryot

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-66733?

An unbounded memory allocation vulnerability exists in Sonic 3 A.I.R. due to improper handling of incoming UDP packets in the ReceivedPacketCache::enqueuePacket() method. This flaw allows unauthenticated remote attackers to exploit the system by sending a specially crafted UDP packet containing a maximum uint32 value for the mUniquePacketID. As the server processes this packet without any bounds checking, it can lead to excessive memory allocation, ultimately resulting in server crashes due to an uncaught std::bad_alloc exception, which brings the server process to a halt.

Affected Version(s)

sonic3air 0 <= 26.03.28.0

sonic3air 0 <= 26.03.28.0

sonic3air 2492d1882cd2cf1cc1d7415729ce5c4fd686cd4f

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Valentin Lobstein (Chocapikk)
.