CVE-2026-2967
Description
A flaw was found in Cesanta Mongoose. A remote attacker could exploit an improper verification of the source of a communication channel within the TCP Sequence Number Handler. This vulnerability, specifically in the getpeer function, could lead to a Denial of Service (DoS) condition, making the affected system unavailable. While the attack complexity is high and exploitation is difficult, a public exploit has been disclosed.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
To mitigate the risk of a remote Denial of Service, restrict network access to systems running applications that utilize Cesanta Mongoose. Configure firewall rules to limit incoming connections to only trusted hosts and networks. This may impact legitimate network-based functionality of applications relying on Mongoose if not carefully configured.
Understanding the Weakness (CWE)
Access Control,Other
Technical Impact: Gain Privileges or Assume Identity; Varies by Context; Bypass Protection Mechanism
An attacker can access any functionality that is inadvertently accessible to the source.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.