rpm package
opensuse/kronosnet&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kronosnet&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-15812 | Med | 4.8 | < 1.33-2.1 | 1.33-2.1 | Jul 21, 2026 | A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the vali | |
| CVE-2026-15811 | Med | 5.8 | < 1.33-2.1 | 1.33-2.1 | Jul 21, 2026 | A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resid | |
| CVE-2026-15813 | Med | 6.5 | < 1.33-2.1 | 1.33-2.1 | Jul 20, 2026 | A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitti |
- affected < 1.33-2.1fixed 1.33-2.1
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the vali
- affected < 1.33-2.1fixed 1.33-2.1
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resid
- affected < 1.33-2.1fixed 1.33-2.1
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitti