Sploitus

CVE-2026-56099

1 known exploit for CVE-2026-56099

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

Affected products
Openbsd
Openbsd
< 2026-06-18
Fix
Available
CVSS 4.0
6.9 MEDIUM
CVSS 3.1
5.3 MEDIUM
EPSS
0.5% (41th percentile)
Weakness
CWE-125
NVD status
Analyzed
Published
2026-06-18
CVE-2026-56099 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-56099

Proof-of-concept code and exploit modules indexed by Sploitus