openSUSE-SU-2026:21851-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21851-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21851-1
Upstream
CVE (3)
  • CVE-2026-15811
  • CVE-2026-15812
  • CVE-2026-15813
Related
Published
2026-09-15T06:42:31Z
Modified
2026-09-17T18:23:13Z
Summary
Security update for kronosnet
Details

This update for kronosnet fixes the following issues:

  • CVE-2026-15811: improper sanitization of sensitive memory locations following cryptographic configuration adjustments can lead to potential exposure of encryption keys (bsc#1271923).
  • CVE-2026-15812: improper verification of packet origins allows for access control list (ACL) bypass via ID spoofing (bsc#1271924).
  • CVE-2026-15813: improper validation during fragment reassembly can trigger memory corruption or out-of-bounds memory access (bsc#1271925).
References

Affected packages

openSUSE:Leap 16.0 / kronosnet

Package

Name
kronosnet
Purl
pkg:rpm/opensuse/kronosnet&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.30-160000.4.1

Ecosystem specific

{
    "binaries":  [
        {
            "libknet-devel":  "1.30-160000.4.1",
            "libknet1":  "1.30-160000.4.1",
            "libknet1-compress-bzip2-plugin":  "1.30-160000.4.1",
            "libknet1-compress-lz4-plugin":  "1.30-160000.4.1",
            "libknet1-compress-lzma-plugin":  "1.30-160000.4.1",
            "libknet1-compress-lzo2-plugin":  "1.30-160000.4.1",
            "libknet1-compress-plugins-all":  "1.30-160000.4.1",
            "libknet1-compress-zlib-plugin":  "1.30-160000.4.1",
            "libknet1-compress-zstd-plugin":  "1.30-160000.4.1",
            "libknet1-crypto-nss-plugin":  "1.30-160000.4.1",
            "libknet1-crypto-openssl-plugin":  "1.30-160000.4.1",
            "libknet1-crypto-plugins-all":  "1.30-160000.4.1",
            "libknet1-plugins-all":  "1.30-160000.4.1",
            "libnozzle-devel":  "1.30-160000.4.1",
            "libnozzle1":  "1.30-160000.4.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21851-1.json"