CVE-2026-56099 Details
Description
OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.
A remote out-of-bounds read vulnerability has been identified in OpenBSD versions prior to the June 18, 2026 commit 6a23123. The issue resides in the 'mpls_do_error' function within 'sys/netmpls/mpls_input.c'. This vulnerability allows remote attackers to disclose adjacent kernel stack memory by sending crafted MPLS frames that contain 16 labels without a Bottom-of-Stack (BoS) bit set. The vulnerability is triggered when the 'mpls_do_error' function processes these frames, leading to the unintentional leakage of 4 bytes of kernel stack memory through the ICMP/MPLS error response.
Users can update to OpenBSD versions after the June 18, 2026 commit 6a23123 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2026/Jun/17 | CVE | ExploitMailing ListPatchThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/19/3 | CVE | ExploitMailing ListPatchThird Party Advisory |
| https://github.com/openbsd/src/commit/6a23123ec05f1eb29cfcaae0f3a468b2e1983cfd | [email protected] | Patch |
| https://pop.argus-systems.ai/advisory/adv-040.html | [email protected] | ExploitPatchThird Party Advisory |
| https://www.vulncheck.com/advisories/openbsd-mpls-do-error-kernel-stack-memory-disclosure-via-mpls-input | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openbsd openbsd | < 2026-06-18 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 27, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 21, 2026 | CVE Modified | CVE |
| Jun 19, 2026 | CVE Modified | CVE |
| Jun 18, 2026 | New CVE Received | [email protected] |