Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.8

CVE-2026-15811: Kronosnet: Encryption Keys Left in Memory

CVE-2026-15811 CVE-2026-15811
Summary

A security issue affects Kronosnet versions 1.35 and earlier. If an attacker can access the memory of a Kronosnet system, they may be able to obtain the encryption keys and decrypt sensitive information. To protect against this, update to the latest version of Kronosnet or take steps to prevent memory access by unauthorized individuals.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
red hat red hat enterprise linux 10 All versions
red hat red hat enterprise linux 8 All versions
red hat red hat enterprise linux 9 All versions
red hat red hat openshift container platform 4 All versions
Original title
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes...
Original description
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
mitre CVSS3.1 5.8
Vulnerability type
CWE-212
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026