PatchSiren cyber security CVE debrief
CVE-2026-56099 openbsd CVE debrief
CVE-2026-56099 is an out-of-bounds read vulnerability in the mpls_do_error function within OpenBSD's sys/netmpls/mpls_input.c. This vulnerability allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set. The vulnerability was patched in OpenBSD commit 6a23123 on June 18, 2026. System administrators and security teams responsible for OpenBSD systems, especially those exposed to untrusted networks, should prioritize patching this vulnerability to prevent potential kernel stack memory disclosure.
- Vendor
- openbsd
- Product
- src
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-18
- Original CVE updated
- 2026-07-14
- Advisory published
- 2026-06-18
- Advisory updated
- 2026-07-14
Who should care
System administrators and security teams responsible for OpenBSD systems, especially those exposed to untrusted networks, should prioritize patching this vulnerability to prevent potential kernel stack memory disclosure. This includes teams managing OpenBSD deployments in cloud environments, data centers, or other settings where network exposure is a concern.
Technical summary
The mpls_do_error function in OpenBSD's sys/netmpls/mpls_input.c is vulnerable to an out-of-bounds read attack. By sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set, remote attackers can exploit this vulnerability to disclose kernel stack memory. This issue was addressed in OpenBSD commit 6a23123 on June 18, 2026. The vulnerability affects OpenBSD systems prior to this commit, and system administrators should prioritize patching to prevent potential kernel stack memory disclosure.
Defensive priority
High
Recommended defensive actions
- Apply the official patch from OpenBSD (commit 6a23123) to vulnerable systems.
- Restrict access to MPLS services to trusted sources only.
- Implement network monitoring to detect suspicious MPLS traffic.
- Consider using network segmentation to limit the impact of a potential exploit.
- Regularly review and update OpenBSD systems to ensure they have the latest security patches.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on June 18, 2026, and last modified on June 27, 2026. The NVD entry is currently Analyzed. The vulnerability was patched in OpenBSD commit 6a23123 on June 18, 2026. Multiple sources, including Vulncheck and Argus Systems, have reported on this vulnerability. The CVE record and NVD entry provide additional context for this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-56099 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-56099
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-56099 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56099
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/openbsd/src/commit/6a23123ec05f1eb29cfcaae0f3a468b2e1983cfd
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://pop.argus-systems.ai/advisory/adv-040.html
[email protected] - Exploit, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openbsd-mpls-do-error-kernel-stack-memory-disclosure-via-mpls-input
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.