Out-of-bounds read in Mongoose - CVE-2026-52068
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the rx_ndp_na() and rx_ndp_ns() NDP message handlers when processing ICMPv6 neighbor advertisement and neighbor solicitation packets. A remote attacker can send a specially crafted NDP packet to cause a denial of service.
Exploitation requires access to the same local network segment, and the issue affects IPv6-enabled interfaces using the built-in TCP/IP stack on bare-metal embedded platforms.