Description
A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".
Published: 2026-08-04
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

To mitigate this issue, avoid exposing stunnel services to untrusted clients. Restrict access to these services to trusted networks only.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Stunnel
Stunnel stunnel
Vendors & Products Stunnel
Stunnel stunnel

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title stunnel: Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Tue, 04 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".
Title stunnel: Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

threat_severity

Moderate


Subscriptions

Redhat Enterprise Linux
Stunnel Stunnel
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-04T14:21:27.297Z

Reserved: 2026-08-04T07:03:23.572Z

Link: CVE-2026-70368

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-04T10:30:31Z

Links: CVE-2026-70368 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:00:03Z

Weaknesses