Source: kronosnet Version: 1.33-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for kronosnet. CVE-2026-15811[0]: | A vulnerability was found in kronosnet's (version <=1.34) | cryptographic configuration management. The framework does not | correctly zero-out or wipe sensitive memory segments after executing | changes to its cryptographic configuration. This omission leaves raw | encryption keys resident in memory after the associated structures | are freed. A local attacker capable of leveraging memory disclosure | techniques could exploit this flaw to retrieve the active encryption | key, allowing them to decrypt cluster network communications or | inject malicious packets to cause severe high-availability cluster | instability. CVE-2026-15812[1]: | A vulnerability was found in the internal Access Control List (ACL) | subsystem of kronosnet (Version affected: <= 1.34). When the | framework is explicitly configured to manage dynamic links | (accepting network traffic from any IP address) without network | payload encryption, the validation architecture implicitly trusts | the link ID provided within incoming data packets. A remote, | unauthenticated attacker can exploit this lack of validation by | spoofing a legitimate link ID inside crafted network frames. This | allows the attacker to fully bypass the ACL framework and inject | arbitrary data packets into the application layer, potentially | leading to data corruption or service instabilities. CVE-2026-15813[2]: | A vulnerability was found in the network packet de-fragmentation | engine of kronosnet (Version affected <= 1.34). The internal | reassembly code does not properly validate sequence numbers of | incoming payload fragments. An attacker can exploit this lack of | verification by transmitting malformed packets with corrupted | sequence parameters. Under specific conditions, this forces the | packet processing layer to parse data outside the designated bounds | of the internal memory structures, causing an out-of-bounds memory | access or heap corruption. This behavior can result in sudden | application crashes or system instability. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15811 https://www.cve.org/CVERecord?id=CVE-2026-15811 [1] https://security-tracker.debian.org/tracker/CVE-2026-15812 https://www.cve.org/CVERecord?id=CVE-2026-15812 [2] https://security-tracker.debian.org/tracker/CVE-2026-15813 https://www.cve.org/CVERecord?id=CVE-2026-15813 Regards, Salvatore

