CVE-2026-76989 PUBLISHED

liftoff-sr CIPster TCP Encapsulation Receive Path encap.cc out-of-bounds

Assigner: VulDB
Reserved: 20.08.2026 Published: 20.08.2026 Updated: 20.08.2026

A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the file source/src/enet_encap/encap.cc of the component TCP Encapsulation Receive Path. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is e8e9dba09bf56962807d3504b783ccdb6287f3e4. To fix this issue, it is recommended to deploy a patch.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor liftoff-sr
Product CIPster
Versions
  • Version 1802525be27d33e19a9a83c163e331a1d13b1892 is affected

Credits

  • Carnegie (VulDB User) reporter

References

Problem Types

  • Out-of-Bounds Read CWE
  • Memory Corruption CWE