目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-15811— Kronosnet 加密密钥在内存中泄露漏洞

CVSS 5.8 · Medium
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-15811 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
敏感数据的不恰当跨边界移除
来源: 美国国家漏洞数据库 NVD

受影响产品

厂商产品影响版本CPE订阅
Red HatRed Hat Enterprise Linux 10-cpe:/o:redhat:enterprise_linux:10
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9
Red HatRed Hat OpenShift Container Platform 4-cpe:/a:redhat:openshift:4

二、漏洞 CVE-2026-15811 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-15811 的情报信息

登录查看更多情报信息。

CVE-2026-15811 厂商安全公告 (1)

CVE-2026-15811 其他参考 (1)

同批安全公告 · Red Hat · 2026-07-21 · 共 16 条

CVE-2026-598518.8 HIGHLibssh 身份验证绕过漏洞:缺少 GSSAPI 主体检查
CVE-2026-164457.5 HIGHDracut networkmanager模块DHCP命令注入导致远程代码执行漏洞
CVE-2026-159276.8 MEDIUMQuay 仓库级镜像远程服务器请求伪造漏洞
CVE-2026-153706.7 MEDIUMLibssh SFTP服务器长名构造栈缓冲区溢出漏洞
CVE-2026-164616.5 MEDIUMRpcbind 栈缓冲区溢出漏洞
CVE-2026-598446.5 MEDIUMLibssh SFTP读取长度过大导致拒绝服务漏洞
CVE-2026-598436.5 MEDIUMLibssh 通过零通告通道包大小的拒绝服务漏洞
CVE-2026-598475.9 MEDIUMLibssh 通过 OpenSSL AES-GCM 标签验证降级完整性漏洞
CVE-2026-598485.3 MEDIUMLibssh SFTP响应中未知请求ID导致拒绝服务漏洞
CVE-2026-598455.3 MEDIUMLibssh 通过未检查的proxycommand fork()失败导致拒绝服务漏洞
CVE-2026-158124.8 MEDIUMKronosnet 通过未加密动态链路的链接ID伪造绕过访问控制
CVE-2026-598504.3 MEDIUMlibssh 关闭通道回调时使用已释放内存漏洞
CVE-2026-598463.9 LOWLibssh 通过代理命令用户名扩展的信息泄露漏洞
CVE-2026-598423.7 LOWLibssh GSSAPI Curve25519 公钥信息泄露漏洞
CVE-2026-598493.1 LOWLibssh 自动证书认证循环拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-15811

暂无评论


发表评论