Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56123

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.

A flaw was found in socat. A remote attacker, acting as a malicious SOCKS5 proxy server, can exploit a heap-based buffer overflow. This vulnerability, caused by a sign-extension flaw in the DOMAINNAME reply parser, allows the attacker to write arbitrary data to memory. This could lead to arbitrary code execution or a denial of service.

Отчет

This issue affected socat versions 1.8.0.0 - 1.8.1.1. Red Hat Enterprise Linux 7, 8, 9, and 10 include older socat 1.7.* versions and are therefore not affected by this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10socatNot affected
Red Hat Enterprise Linux 7socatNot affected
Red Hat Enterprise Linux 8socatNot affected
Red Hat Enterprise Linux 9socatNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2493004socat: Socat: Heap-based buffer overflow allows arbitrary code execution via malicious SOCKS5 proxy server

EPSS

Процентиль: 45%
0.00548
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.

CVSS3: 8.1
nvd
3 месяца назад

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.

msrc
около 1 месяца назад

socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser

CVSS3: 8.1
debian
3 месяца назад

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer ove ...

CVSS3: 8.1
github
3 месяца назад

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.

EPSS

Процентиль: 45%
0.00548
Низкий

8.1 High

CVSS3