CVE-2026-21863: Network Packet Header Oob Read

Missing bounds check for a packet extension header size prior to accessing its internal length field. This can cause an out-of-bounds read, potentially leading to a Denial of Service or unauthorized information disclosure.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-21863-network-packet-header-oob-read --engine opengrep

Description

Missing bounds check for a packet extension header size prior to accessing its internal length field. This can cause an out-of-bounds read, potentially leading to a Denial of Service or unauthorized information disclosure.