CVE-2026-15813

NameCVE-2026-15813
DescriptionA vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142847

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kronosnet (PTS)bullseye1.20-4vulnerable
bookworm1.25-1vulnerable
trixie1.31-1vulnerable
forky, sid1.33-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kronosnetsource(unstable)(unfixed)1142847

Notes

[trixie] - kronosnet <no-dsa> (Minor issue)
[bookworm] - kronosnet <postponed> (Minor issue)
[bullseye] - kronosnet <postponed> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2500854

Search for package or bug name: Reporting problems