Описание
OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.
Ссылки
- Patch
- ExploitPatchThird Party Advisory
- Third Party Advisory
- ExploitMailing ListPatchThird Party Advisory
- ExploitMailing ListPatchThird Party Advisory
Уязвимые конфигурации
EPSS
5.3 Medium
CVSS3
Дефекты
Связанные уязвимости
OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.
Уязвимость функции mpls_do_error() сценария sys/netmpls/mpls_input.c операционной системы OpenBSD, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.3 Medium
CVSS3