CVE-2026-56099: OpenBSD

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

Affected products

  • OpenBSD OpenBSD: before 2026-06-18 (fixed in 2026-06-18)

Published 2026-06-18. Last modified 2026-07-14.