Impact
A flaw in the kronosnet packet reassembly code allows an attacker, by sending malformed fragments, to bypass sequence number checks and force the system to read or write beyond the bounds of its memory buffers. The resulting out‑of‑bounds access or heap corruption can crash the application or destabilize the host, potentially leading to denial of service. The weakness is identified as a buffer overread or overwrite (CWE‑787).
Affected Systems
The vulnerability impacts installations of kronosnet version 1.34 or earlier, including Red Hat Enterprise Linux 8, 9, and 10 and Red Hat OpenShift Container Platform 4. The affected components are the network packet de‑fragmentation engine used in those distributions.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows the exploitation probability is currently very low. The vulnerability is not listed in CISA's KEV catalog. The likely attack surface is remote network traffic that delivers specially crafted fragment packets, as the flaw involves inbound packet parsing. No public proof‑of‑concept exploitation has been reported, but the description allows the possibility of denial of service.
OpenCVE Enrichment