{"id":"CVE-2026-44254","summary":"Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path","details":"Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes a pointer inside its stack buffer to ReadSecMSG(), and src/os_crypto/shared/msgs.c decompresses up to OS_MAXSTR bytes at that offset. For an encrypted agent message on TCP port 1514 that expands to 65,536 bytes, os_zlib_uncompress() writes a terminating null byte beyond the end of the destination buffer. The resulting stack out-of-bounds write in the root-level remoted daemon can crash message processing and disrupt agent communications. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.","aliases":["GHSA-9wm4-fp6c-hqgq"],"modified":"2026-08-21T08:19:09.200235Z","published":"2026-08-19T16:09:55.307Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-131","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44254.json"},"references":[{"type":"WEB","url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.6"},{"type":"WEB","url":"https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44254.json"},{"type":"ADVISORY","url":"https://github.com/wazuh/wazuh/security/advisories/GHSA-9wm4-fp6c-hqgq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44254"},{"type":"FIX","url":"https://github.com/wazuh/wazuh/commit/96772487fbdecd43cc83e284ee7aeb45e3cfcd96"},{"type":"FIX","url":"https://github.com/wazuh/wazuh/pull/35773"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wazuh/wazuh","events":[{"introduced":"0"},{"introduced":"cddd833300cb5af494ba7dab31192bae649eb184"},{"fixed":"44c2925b46bd058d2426bd44ed1b3e5d7b7b03b4"},{"fixed":"b58b3b2552497639b1b2a2b23e8de87e4ce9cf02"},{"fixed":"96772487fbdecd43cc83e284ee7aeb45e3cfcd96"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0"},{"fixed":"4.14.6"},{"introduced":"5.0.0-beta1"},{"fixed":"5.0.0-beta2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v4.14.6-rc2","coverity-w26-4.14.6","v4.14.6-rc1","coverity-w20-4.14.6","coverity-w19-4.14.6","coverity-w17-4.14.6","v5.0.0-beta1","coverity-w15-4.14.5","coverity-w13-4.14.5","coverity-w12-4.14.5","v4.14.1","v4.14.3-rc1","v3.13.1","v3.13.0","v3.12.0","v3.8.0","v3.7.0","v3.6.1","v3.6.0","v3.5.0","v3.2.0","v3.1.0","v2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44254.json","vanir_signatures_modified":"2026-08-21T08:19:09Z","vanir_signatures":[{"digest":{"function_hash":"312243982569551611979848641343126168055","length":8736},"id":"CVE-2026-44254-064d9c12","signature_type":"Function","signature_version":"v1","source":"https://github.com/wazuh/wazuh/commit/96772487fbdecd43cc83e284ee7aeb45e3cfcd96","target":{"file":"src/remoted/secure.c","function":"HandleSecureMessage"},"deprecated":false},{"digest":{"function_hash":"315877931027140181476030362078766908548","length":6598},"id":"CVE-2026-44254-90fc8fba","signature_type":"Function","signature_version":"v1","source":"https://github.com/wazuh/wazuh/commit/96772487fbdecd43cc83e284ee7aeb45e3cfcd96","target":{"file":"src/os_crypto/shared/msgs.c","function":"ReadSecMSG"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/wazuh/wazuh/commit/96772487fbdecd43cc83e284ee7aeb45e3cfcd96","target":{"file":"src/os_crypto/shared/msgs.c"},"deprecated":false,"digest":{"line_hashes":["224192053887850630141301157970159709412","1934363434683992422529634735717275013","7820595461000133935349335166793396905","95709601146541220411544924594655539723","129768064923975732652346105513653722342","253832570521790769986913736733281938655","319075114133320055566367442343432001963","113094608059400047133669508774771873773","75341247743195882645120623028793052665","30551880990697681489608382798119257405","330995547033482582752710362370437350042","89218813748563267774086358010174112117","148055596128184117379436574595381093080","338192102921520976276544426848115678431","44317742669454298051090490073083868752","147830074730980995479360925536847025876"],"threshold":0.9},"id":"CVE-2026-44254-a99100f2"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}