#VU121070 Out-of-bounds read in Snort - CVE-2026-20027
Published: January 7, 2026 / Updated: January 29, 2026
Snort
Sourcefire
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when handling DCE/RPC requests. A remote attacker can send a large number of DCE/RPC requests through an established connection that is inspected by Snort 3 and obtain sensitive information in the Snort 3 data stream.