OpenBSD disclosed CVE-2026-56099, a medium-severity flaw in the MPLS subsystem that can expose kernel stack memory to a remote attacker when MPLS is enabled on an interface. The bug is in mpls_do_error() in sys/netmpls/mpls_input.c, where a crafted MPLS packet with 16 labels and no Bottom-of-Stack bit causes the kernel to copy 17 shim headers from a 16-entry local stack array, leaking 4 bytes of adjacent kernel stack data in an ICMP/MPLS error response.
The issue affects OpenBSD -current before the fix and traces back to code introduced in 2010 in the ICMP/MPLS error-handling path. Exploitation requires an attacker to send an MPLS frame with EtherType 0x8847, an outer label TTL of 1, and an IPv4 inner payload; researchers at Argus Systems reported the vulnerability, and OpenBSD corrected it by rejecting label stacks that reach the maximum depth without a BoS bit.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
OpenBSD fixed the MPLS over-read vulnerability by rejecting label stacks that reach the maximum depth without a Bottom-of-Stack bit set. The flaw affected OpenBSD -current prior to this fix.
Argus Systems reported a vulnerability in OpenBSD's MPLS error-handling path that can leak 4 bytes of adjacent kernel stack memory via a crafted MPLS packet. The issue was later tracked as CVE-2026-56099.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcegithub.com
Open sourceseclists.org
Open sourcepop.argus-systems.ai
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.