CVE-2026-44251: Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a sizet integer underflow in oscrypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the manager, immediately disconnecting all agents from the manager. A second code path reached by the same underflow may allow heap memory corruption. This issue has been fixed in version 4.14.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wazuh (wazuh-remoted)to a version that resolves this vulnerability.Fixed in 4.14.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44251?
CVE-2026-44251 has a medium severity score of 6.5.
What impact does CVE-2026-44251 have on Wazuh?
CVE-2026-44251 can cause a denial of service (DoS) and potential heap overflow due to a size_t underflow in the msgs.c component.
How do I fix CVE-2026-44251?
To mitigate CVE-2026-44251, upgrade Wazuh to version 4.14.5 or later.
In which Wazuh versions is CVE-2026-44251 present?
CVE-2026-44251 affects Wazuh versions from 3.0.0 up to, but not including, 4.14.5.
What should I do if I am using an affected version of Wazuh?
If using an affected version of Wazuh, it is recommended to upgrade to the latest version to address the vulnerability.