{"id":"openSUSE-SU-2026:21851-1","summary":"Security update for kronosnet","details":"This update for kronosnet fixes the following issues:\n\n- CVE-2026-15811: improper sanitization of sensitive memory locations following cryptographic configuration adjustments\n  can lead to potential exposure of encryption keys (bsc#1271923).\n- CVE-2026-15812: improper verification of packet origins allows for access control list (ACL) bypass via ID spoofing\n  (bsc#1271924).\n- CVE-2026-15813: improper validation during fragment reassembly can trigger memory corruption or out-of-bounds memory\n  access (bsc#1271925).\n","modified":"2026-09-17T18:23:13.848576762Z","published":"2026-09-15T06:42:31Z","related":["CVE-2026-15811","CVE-2026-15812","CVE-2026-15813"],"upstream":["CVE-2026-15811","CVE-2026-15812","CVE-2026-15813"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271925"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15811"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15812"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15813"}],"affected":[{"package":{"name":"kronosnet","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/kronosnet&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.30-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"libknet1-compress-zstd-plugin":"1.30-160000.4.1","libnozzle1":"1.30-160000.4.1","libknet1-crypto-openssl-plugin":"1.30-160000.4.1","libknet1-crypto-plugins-all":"1.30-160000.4.1","libknet1-compress-bzip2-plugin":"1.30-160000.4.1","libknet1":"1.30-160000.4.1","libknet1-compress-lzma-plugin":"1.30-160000.4.1","libknet1-compress-lz4-plugin":"1.30-160000.4.1","libknet1-compress-plugins-all":"1.30-160000.4.1","libknet1-crypto-nss-plugin":"1.30-160000.4.1","libknet-devel":"1.30-160000.4.1","libknet1-compress-zlib-plugin":"1.30-160000.4.1","libnozzle-devel":"1.30-160000.4.1","libknet1-compress-lzo2-plugin":"1.30-160000.4.1","libknet1-plugins-all":"1.30-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21851-1.json"}}],"schema_version":"1.9.0"}