CVE-2026-15811

NameCVE-2026-15811
DescriptionA vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142847

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kronosnet (PTS)bullseye1.20-4vulnerable
bookworm1.25-1vulnerable
trixie1.31-1vulnerable
forky, sid1.33-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kronosnetsource(unstable)(unfixed)1142847

Notes

[trixie] - kronosnet <no-dsa> (Minor issue)
[bookworm] - kronosnet <postponed> (Minor issue)
[bullseye] - kronosnet <postponed> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2500849

Search for package or bug name: Reporting problems