目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-15811— Kronosnet 信息泄露漏洞

CVSS 5.8 · Medium EPSS 0.06% · P0

影响版本矩阵 4

获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-15811 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes
来源: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
敏感数据的不恰当跨边界移除
来源: CVE Program / CVE List V5
Vulnerability Title
Kronosnet 信息泄露漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Kronosnet Kronosnet是Kronosnet组织的一个网络抽象层,专为高可用性用例而设计,其中冗余、安全性、容错性和快速故障转移是核心要求。 Kronosnet存在信息泄露漏洞,该漏洞源于密码配置管理未正确清理敏感内存段,导致加密密钥残留,本地攻击者可利用内存泄露技术获取密钥,解密集群通信或注入恶意分组造成高可用集群不稳定。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
Red HatRed Hat Enterprise Linux 10-cpe:/o:redhat:enterprise_linux:10
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9
Red HatRed Hat OpenShift Container Platform 4-cpe:/a:redhat:openshift:4

二、漏洞 CVE-2026-15811 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-15811 的情报信息

登录查看更多情报信息。

CVE-2026-15811 厂商安全公告 (2)

同批安全公告 · Red Hat · 2026-07-21 · 共 20 条

CVE-2026-598518.8 HIGHlibssh 授权问题漏洞
CVE-2026-164937.8 HIGHansible 命令注入漏洞
CVE-2026-164457.5 HIGHdracutdevs dracut 命令注入漏洞
CVE-2026-159276.8 MEDIUMRed Hat Quay 服务端请求伪造漏洞
CVE-2026-153706.7 MEDIUMlibssh 缓冲区错误漏洞
CVE-2026-598436.5 MEDIUMlibssh 资源管理错误漏洞
CVE-2026-164616.5 MEDIUMrpcbind project rpcinfo 缓冲区错误漏洞
CVE-2026-598446.5 MEDIUMlibssh 资源管理错误漏洞
CVE-2026-598475.9 MEDIUMlibssh 硬件供应链问题漏洞
CVE-2026-598455.3 MEDIUMlibssh 安全漏洞
CVE-2026-598485.3 MEDIUMlibssh 安全漏洞
CVE-2026-158124.8 MEDIUMKronosnet 授权问题漏洞
CVE-2026-598504.3 MEDIUMlibssh 资源管理错误漏洞
CVE-2026-125484.2 MEDIUMGNOME libsoup 缓冲区错误漏洞
CVE-2026-598463.9 LOWlibssh 安全漏洞
CVE-2026-598423.7 LOWlibssh 缓冲区错误漏洞
CVE-2026-125473.4 LOWlibsoup 信息泄露漏洞
CVE-2026-598493.1 LOWlibssh 资源管理错误漏洞
CVE-2026-165172.9 LOWlibarchive 数字错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-15811

暂无评论


发表评论