OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.
References
| Link | Resource |
|---|---|
| https://github.com/openbsd/src/commit/6a23123ec05f1eb29cfcaae0f3a468b2e1983cfd | Patch |
| https://pop.argus-systems.ai/advisory/adv-040.html | Exploit Patch Third Party Advisory |
| https://www.vulncheck.com/advisories/openbsd-mpls-do-error-kernel-stack-memory-disclosure-via-mpls-input | Third Party Advisory |
| http://seclists.org/fulldisclosure/2026/Jun/17 | Exploit Mailing List Patch Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/19/3 | Exploit Mailing List Patch Third Party Advisory |
Configurations
History
27 Jun 2026, 23:53
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openbsd/src/commit/6a23123ec05f1eb29cfcaae0f3a468b2e1983cfd - Patch | |
| References | () https://pop.argus-systems.ai/advisory/adv-040.html - Exploit, Patch, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/openbsd-mpls-do-error-kernel-stack-memory-disclosure-via-mpls-input - Third Party Advisory | |
| References | () http://seclists.org/fulldisclosure/2026/Jun/17 - Exploit, Mailing List, Patch, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/19/3 - Exploit, Mailing List, Patch, Third Party Advisory | |
| CPE | cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* | |
| First Time |
Openbsd openbsd
Openbsd |
21 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-18 20:16
Updated : 2026-07-14 22:17
NVD link : CVE-2026-56099
Mitre link : CVE-2026-56099
CVE.ORG link : CVE-2026-56099
JSON object : View
Products Affected
openbsd
- openbsd
CWE
CWE-125
Out-of-bounds Read
