Description
Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an integer overflow in the µD3TN v0.15.0 TCPCLv3 handshake that leads to a heap overflow, enabling an attacker to reliably crash the application. This weakness corresponds to CWE‑190. The impact is loss of service for the affected system, without evidence of code execution or data theft. Local or remote users who can initiate a TCPCLv3 handshake with the vulnerable software can trigger the DoS.

Affected Systems

The affected product is D3TN GmbH's µD3TN. Only version 0.15.0 is known to contain the flaw; the latest published update, 0.15.1, resolves the issue and higher versions are assumed safe.

Risk and Exploitability

The CVSS score of 7.5 indicates a high potential for disruption. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote network-based connection that initiates the TCPCLv3 handshake; this inference is drawn from the mention of a network‑level protocol and the nature of the affected component.

Generated by OpenCVE AI on September 19, 2026 at 18:33 UTC.

Remediation

Vendor Solution

Upgrade to version 0.15.1 or above.


OpenCVE Recommended Actions

  • Upgrade µD3TN to version 0.15.1 or later as provided by the vendor.
  • Restrict or block inbound traffic on the port(s) used for µD3TN TCPCLv3 handshakes to reduce the opportunity for abuse.
  • Apply network rate limiting or intrusion prevention controls to mitigate repeated handshake attempts that could cause a denial of service.

Generated by OpenCVE AI on September 19, 2026 at 18:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared D3tn
D3tn ud3tn
Vendors & Products D3tn
D3tn ud3tn

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
Title Integer Overflow or Wraparound in µD3TN
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-18T17:23:04.623Z

Reserved: 2026-09-18T13:14:21.737Z

Link: CVE-2026-93652

cve-icon Vulnrichment

Updated: 2026-09-18T17:16:47.670Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:21.917

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-93652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound