CVE-2026-56123

EUVD-2026-39455
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 23.1%
Affected Products (NVD)
VendorProductVersion
dest-unreachsocat
1.8.0.0 ≤
𝑥
< 1.8.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
socat
bookworm
1.7.4.4-2
fixed
bullseye
1.7.4.1-3
fixed
forky
1.8.1.3-2
fixed
sid
1.8.1.3-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
socat
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 1.8.0.0-4ubuntu0.1
released
questing
ignored
resolute
Fixed 1.8.1.1-1ubuntu0.1
released
trusty
not-affected