PatchSiren

irontec CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL irontec CVE published 2026-09-12

CVE-2026-90558

A stack buffer overflow vulnerability exists in sngrep through version 1.8.4. The vulnerability is caused by SIP attribute formatting routines that do not properly handle header values exceeding the 255-byte buffer limit. This allows attackers to craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields, potentially leading to crashes or arbitrary code execution during packet p [truncated]