PT-2026-60611 · Wazuh · Wazuh
CVE-2026-44251
·
Published
2026-07-17
·
Updated
2026-07-20
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Wazuh versions 3.0.0 through 4.14.4
Description
A size t integer underflow occurs in the
os crypto/shared/msgs.c:389 file. This flaw allows an enrolled agent to crash the wazuh-remoted process on the manager, which results in the immediate disconnection of all agents. Additionally, a separate code path triggered by the same underflow may lead to heap memory corruption, a condition where the program writes data outside the boundaries of a memory block allocated on the heap.Recommendations
Update to version 4.14.5.
Exploit
Fix
DoS
Integer Underflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wazuh