CVE-2026-15813
Last modified
CVE-2026-15813 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments.
Description
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
| Red Hat | Red Hat OpenShift Container Platform 4 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-15813?
How severe is CVE-2026-15813?
How do I fix CVE-2026-15813?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15805Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-15809A flaw was found in CRI-O. The fix for a previous vulnerabil…7.8
- CVE-2026-1581The wpForo Forum plugin for WordPress is vulnerable to time-…7.5
- CVE-2026-15810A Cross-Site Scripting (XSS) vulnerability in Google Cloud L…8.7
- CVE-2026-15811A vulnerability was found in kronosnet's (version <=1.34) cr…5.8
- CVE-2026-15812A vulnerability was found in the internal Access Control Lis…4.8
- CVE-2026-15816A flaw was found in dracut. The die() error-handling functio…7.5
- CVE-2026-1582The WP All Export plugin for WordPress is vulnerable to Sens…3.7
- CVE-2026-15821The SureDash – Community, Courses & Member Dashboard plugin …6.4
- CVE-2026-15827The GutenKit Blocks plugin for WordPress is vulnerable to un…5.3
- CVE-2026-15829A SQL injection (CWE-89) and security boundary bypass (CWE-8…8.6
- CVE-2026-15830An issue was discovered in Django 5.2 before 5.2.17 and 6.0 …6.9
Are you affected by CVE-2026-15813?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
