CVE-2026-56123

Name
CVE-2026-56123
Description
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com http://www.dest-unreach.org/socat/CHANGES
disclosure@vulncheck.com https://www.vulncheck.com/advisories/socat-heap-buffer-overflow-via-socks5-reply-parser

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:dest-unreach:socat:*:*:*:*:*:*:*:* socat >= 1.8.0.0 < 1.8.1.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
socat edge-main 1.8.1.2-r0 mio <miyopan@e.email> fixed
socat edge-main 1.8.1.1-r0 mio <miyopan@e.email> possibly vulnerable
socat edge-main 1.8.1.0-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
socat edge-main 1.8.0.3-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
socat edge-main 1.8.0.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
socat edge-main 1.8.0.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
socat edge-main 1.8.0.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
socat 3.24-main 1.8.1.2-r0 mio <miyopan@e.email> fixed
socat 3.24-main 1.8.1.1-r0 mio <miyopan@e.email> possibly vulnerable
socat 3.23-main 1.8.1.2-r0 Celeste <cielesti@protonmail.com> fixed
socat 3.23-main 1.8.0.3-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
socat 3.22-main 1.8.1.2-r0 Celeste <cielesti@protonmail.com> fixed
socat 3.22-main 1.8.0.3-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
socat 3.21-main 1.8.0.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
socat 3.21-main 1.8.0.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
socat 3.20-main 1.8.0.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
socat 3.19-main 1.8.0.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable