CVE-2026-57226

critical

Description

The vulnerability exists due to a use-after-free (UAF) condition inside the TCP stream reassembly layer. When a connection undergoes abrupt termination sequences (such as an interleaving flood of RST and FIN packets), the flow tracking engine frees network payload metadata objects prematurely while active parsing references are still attached.

Details

Source: Mitre, NVD

Published: 2026-07-23

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Severity: Critical