VYPR
Medium severity5.3NVD Advisory· Published Jun 18, 2026· Updated Jul 14, 2026

CVE-2026-56099

CVE-2026-56099

Description

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • OpenBSD/OpenBSD3 versions
    cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*range: <2026-06-18
    • (no CPE)range: <commit 6a23123
    • (no CPE)
  • OpenBSD/Srcllm-fuzzy
    Range: <commit 6a23123

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.