PT-2026-6366 · Crates.Io · Mnl
Published
2026-01-09
·
Updated
2026-01-09
CVSS v4.0
2.0
Low
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P |
The function
mnl::cb run is marked as safe but exhibits unsound behavior when processing malformed Netlink message buffers.Passing a crafted byte slice to
mnl::cb run can trigger memory violations. The function does not sufficiently validate the input buffer structure before processing, leading to out-of-bounds reads.This vulnerability allows an attacker to cause a Denial of Service (segmentation fault) or potentially read unmapped memory by providing a malformed Netlink message.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mnl