Description
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.
Published: 2026-07-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the kronosnet packet reassembly code allows an attacker, by sending malformed fragments, to bypass sequence number checks and force the system to read or write beyond the bounds of its memory buffers. The resulting out‑of‑bounds access or heap corruption can crash the application or destabilize the host, potentially leading to denial of service. The weakness is identified as a buffer overread or overwrite (CWE‑787).

Affected Systems

The vulnerability impacts installations of kronosnet version 1.34 or earlier, including Red Hat Enterprise Linux 8, 9, and 10 and Red Hat OpenShift Container Platform 4. The affected components are the network packet de‑fragmentation engine used in those distributions.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows the exploitation probability is currently very low. The vulnerability is not listed in CISA's KEV catalog. The likely attack surface is remote network traffic that delivers specially crafted fragment packets, as the flaw involves inbound packet parsing. No public proof‑of‑concept exploitation has been reported, but the description allows the possibility of denial of service.

Generated by OpenCVE AI on July 30, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade kronosnet to the latest stable release that contains the reassembly bounds‑check fix
  • Apply any Red Hat security patches released for the affected enterprise Linux releases and OpenShift platform
  • Where patching is delayed, block or rate‑limit unexpected or overly fragmented network traffic using firewall or network policy rules
  • Monitor system logs for sudden application crashes or abnormal packet processing events to detect exploitation attempts

Generated by OpenCVE AI on July 30, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Container Platform
Vendors & Products Redhat openshift Container Platform

Mon, 20 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 20 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.
Title Kronosnet: kronosnet: memory corruption and out-of-bounds access via malformed network packet defragmentation
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-787
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Redhat Enterprise Linux Openshift Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-20T12:08:19.314Z

Reserved: 2026-07-15T10:53:01.091Z

Link: CVE-2026-15813

cve-icon Vulnrichment

Updated: 2026-07-20T12:08:07.753Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-15T11:00:00Z

Links: CVE-2026-15813 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:35:52Z

Weaknesses