CVE-2026-56099: OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input
Published Jun 18, 2026
·Updated
OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mplsdoerror function within sys/netmpls/mplsinput.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.
Affected Software
2 affected components
OpenBSD OpenBSD<6a23123 (2026-06-18)
OpenBSD OpenBSD<2026-06-18
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jun 18, 2026
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56099?
The severity of CVE-2026-56099 is medium with a score of 5.3.
2
How do I fix CVE-2026-56099?
To fix CVE-2026-56099, update to OpenBSD version that includes the commit after 6a23123.
3
What does CVE-2026-56099 affect?
CVE-2026-56099 affects OpenBSD prior to the commit dated June 18, 2026.
4
What type of vulnerability is CVE-2026-56099?
CVE-2026-56099 is an out-of-bounds read vulnerability resulting in kernel stack memory disclosure.
5
How does CVE-2026-56099 exploit occur?
Exploitation of CVE-2026-56099 occurs when remote attackers send crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.