What is CVE-2026-66733?
CVE-2026-66733 is an unbounded memory allocation vulnerability in Sonic 3 A.I.R. before commit 2492d18, located in ReceivedPacketCache::enqueuePacket(). An unauthenticated remote attacker can crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. Users should update to the latest commit to mitigate the issue.
Azərbaycanca: CVE-2026-66733, Sonic 3 A.I.R.-də commit 2492d18-dən əvvəlki versiyalarda `ReceivedPacketCache::enqueuePacket()` funksiyasında hüdudsuz yaddaş ayırma (unbounded memory allocation) zəifliyidir. Autentifikasiya olunmamış uzaq hücumçu `mUniquePacketID` dəyərini maksimum uint32-ə təyin edilmiş xüsusi UDP paketi göndərərək server prosesini çökdürə bilər. Zəiflikdən qorunmaq üçün proqramı ən son commit-ə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which software is affected by CVE-2026-66733?
CVE-2026-66733 affects Sonic 3 A.I.R. versions prior to commit 2492d18.
How can CVE-2026-66733 be mitigated?
Users should update to the latest commit.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.