Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15812

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

Отчет

Red Hat Product Security rates this vulnerability's impact as Low. Although the vulnerability allows an unauthenticated remote attacker to completely bypass the internal ACL layer and introduce arbitrary traffic, it depends entirely on a non-production configuration. The exploit requires that kronosnet actively accept connections from any arbitrary IP (dynamic links) while simultaneously running completely unencrypted traffic. Furthermore, this issue does not affect Red Hat Enterprise Linux High Availability (RHEL HA) or any official layered products, as Red Hat configurations securely enable network encryption by default, entirely mitigating the vulnerability's attack prerequisites.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kronosnetFix deferred
Red Hat Enterprise Linux 8kronosnetFix deferred
Red Hat Enterprise Linux 9kronosnetFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=2500851kronosnet: kronosnet: access control list bypass via link ID spoofing on unencrypted dynamic links

EPSS

Процентиль: 6%
0.00165
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
28 дней назад

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

CVSS3: 4.8
nvd
28 дней назад

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

CVSS3: 4.8
debian
28 дней назад

A vulnerability was found in the internal Access Control List (ACL) su ...

CVSS3: 4.8
github
28 дней назад

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

EPSS

Процентиль: 6%
0.00165
Низкий

4.8 Medium

CVSS3