Remote Out-of-Bounds Read in liftoff-sr CIPster TCP Encapsulation Receive Path
CVE-2026-76989
Key Information:
- Vendor
Liftoff-sr
- Status
- Vendor
- CVE Published:
- 20 August 2026
Badges
What is CVE-2026-76989?
A security vulnerability exists within the liftoff-sr CIPster product that affects the TCP Encapsulation Receive Path. Specifically, an unknown function in the source file source/src/enet_encap/encap.cc allows for out-of-bounds reading due to improper input validation. This flaw can be exploited remotely, potentially compromising system integrity and confidentiality. A patch has been issued to mitigate this issue, ensuring users should deploy it to maintain security.
Affected Version(s)
CIPster 1802525be27d33e19a9a83c163e331a1d13b1892
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
