PT-2026-61543 · Kronosnet · Kronosnet
CVE-2026-15813
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
kronosnet versions prior to 1.35
Description
The network packet de-fragmentation engine contains a flaw where the internal reassembly code fails to properly validate sequence numbers of incoming payload fragments. An attacker can transmit malformed packets with corrupted sequence parameters, forcing the packet processing layer to parse data outside the designated bounds of internal memory structures. This leads to out-of-bounds memory access or heap corruption, which may cause application crashes or system instability.
Recommendations
Update kronosnet to version 1.35 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kronosnet