What is CVE-2026-66360?
This vulnerability lies in the mishandling of specific parameters during normal mode negotiation within the ISO Presentation layer. A missing length check in the processing of encoded presentation data allows an attacker-controlled field with a zero length value to trigger a bounded heap over read condition. Applying vendor-provided updates immediately is recommended for affected systems.
Azərbaycanca: Bu boşluq ISO Təqdimat qatında (Presentation layer) normal rejim danışıqları zamanı parametrlərin işlənməsindəki çatışmazlıqla bağlıdır. Kodlaşdırılmış təqdimat məlumatlarında uzunluq yoxlamasının olmaması, sıfır uzunluqlu attacker-controlled field vasitəsilə məhdud heap over read vəziyyətinə səbəb olur. Təsirə məruz qalan sistemlərdə dərhal təchizatçı tərəfindən təqdim edilən yeniləmələrin tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which protocol layer is affected by CVE-2026-66360?
This vulnerability is related to a flaw in the handling of parameters during normal mode negotiation in the ISO Presentation layer.
What type of memory read issue does CVE-2026-66360 exploitation cause?
The missing length check in encoded presentation data with a zero-length attacker-controlled field triggers a bounded heap over read condition.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.