Sceawere

Vulnerability Detail

CVE-2026-76989UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CIPster Out-Of-Bounds Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
5h ago
Vendor
liftoff-sr
Product
CIPster
Attack Type
Out-of-Bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the file source/src/enet_encap/encap.cc of the component TCP Encapsulation Receive Path. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is e8e9dba09bf56962807d3504b783ccdb6287f3e4. To fix this issue, it is recommended to deploy a patch.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-20T13:19:06.880Z",
  "pubdate": "2026-08-20T13:19:06.880Z",
  "executiveSummary": "An out-of-bounds read vulnerability has been identified in the TCP Encapsulation Receive Path component of liftoff-sr CIPster at commit 1802525be27d33e19a9a83c163e331a1d13b1892, specifically impacting an unknown function within source/src/enet_encap/encap.cc. This security flaw allows remote attackers to trigger memory read operations outside the allocated buffer boundaries.\nThe manipulation of network-based inputs can lead to unauthorized information disclosure, potentially exposing sensitive memory contents or causing application destabilization and denial of service. The risk implications are severe due to the remote attack vector and the public disclosure of an active exploit. Exploitation requires network connectivity to the target system running the vulnerable TCP Encapsulation Receive Path, without explicit prerequisites regarding authentication or user interaction mentioned in the advisory.",
  "technicalDetails": "The vulnerability resides in the source/src/enet_encap/encap.cc file of the TCP Encapsulation Receive Path component within liftoff-sr CIPster. The root cause stems from improper validation of input length or boundary checks during the parsing and processing of incoming network encapsulation data frames. When a maliciously crafted packet or stream is received, the affected function attempts to read memory past the legitimate end of the allocated input buffer.\nExploitation is initiated remotely by an attacker sending specially crafted TCP encapsulation payloads to the vulnerable endpoint. Because the parsing logic fails to properly bound index or pointer arithmetic against the actual size of the received packet data, the extraction routine reads adjacent heap or stack memory locations. Depending on the memory layout and the specific data exposed by the out-of-bounds read, the payload behavior can range from leaking sensitive operational data to crashing the service via an invalid memory access fault.\nThe affected version includes liftoff-sr CIPster commit 1802525be27d33e19a9a83c163e331a1d13b1892. The attack vector is strictly network-exposed through the TCP Encapsulation Receive Path, operating remotely without requiring prior authentication or elevated privileges. Post-exploitation impact primarily centers on information leakage, which may facilitate further attacks by compromising memory layout confidentiality."
}
CVE-2026-76989: CIPster Out-Of-Bounds Read Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere