CVE-2026-44254

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes a pointer inside its stack buffer to ReadSecMSG(), and src/os_crypto/shared/msgs.c decompresses up to OS_MAXSTR bytes at that offset. For an encrypted agent message on TCP port 1514 that expands to 65,536 bytes, os_zlib_uncompress() writes a terminating null byte beyond the end of the destination buffer. The resulting stack out-of-bounds write in the root-level remoted daemon can crash message processing and disrupt agent communications. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 16:17

Updated : 2026-09-09 21:19


NVD link : CVE-2026-44254

Mitre link : CVE-2026-44254

CVE.ORG link : CVE-2026-44254


JSON object : View

Products Affected

No product.

CWE
CWE-131

Incorrect Calculation of Buffer Size

CWE-787

Out-of-bounds Write