CVE-2026-2967: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-2967 is a blind TCP RST injection vulnerability in Cesanta Mongoose's built-in TCP/IP stack (MIP), affecting versions up to and including 7.20. The flaw resides in the getpeer() function within /src/net_builtin.c, which matches incoming TCP segments to existing connections using only the port pair while ignoring the source IP address, and in rx_tcp(), which terminates connections upon receiving a RST flag without validating the sequence number against the receive window. This allows any network-adjacent attacker to terminate arbitrary TCP sessions with a single forged RST packet. It was publicly disclosed on February 23, 2026, with a CVSS v3.1 base score of 3.7 (Low) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The vulnerability has two distinct root causes classified under CWE-940 (Improper Verification of Source of a Communication Channel) and CWE-1285 (Improper Validation of Specified Index, Position, or Offset in Input). First, getpeer() (net_builtin.c:552–555) matches TCP connections solely on the port pair (c->loc.port == pkt->tcp->dport and c->rem.port == pkt->tcp->sport) without ever comparing c->rem.addr against the packet's source IP, enabling any host knowing the port pair to inject packets into an existing connection. Second, rx_tcp() (net_builtin.c:1537–1539) unconditionally calls mg_error(c, "peer RST") upon seeing the RST flag — the code even contains a TODO comment acknowledging the missing window validation — violating RFC 5961 Section 3.2, which requires RCV.NXT <= SEG.SEQ < RCV.NXT + RCV.WND. An additional amplifying factor is that Mongoose's MIP stack uses deterministic TCP Initial Sequence Numbers derived from the ephemeral port number, making future session hijacking feasible after a successful RST injection (PoC Write-up).

Impact

Successful exploitation results in a denial-of-service condition: an attacker can continuously terminate any TCP connection to a Mongoose MIP device — including HTTP, MQTT, and WebSocket sessions — preventing legitimate clients from maintaining sessions. There is no confidentiality or integrity impact under the primary attack scenario; however, the deterministic TCP ISN generation (ISN derived from the ephemeral port number) means a follow-on attacker could predict sequence numbers for subsequent connections, potentially enabling TCP session hijacking beyond mere termination. The impact is scoped to the vulnerable Mongoose instance and does not directly facilitate lateral movement, but persistent DoS against embedded or IoT devices using Mongoose could disrupt critical operational functions (PoC Write-up, Red Hat Bugzilla).

Exploitability

A public proof-of-concept exploit is available on GitHub, authored by researcher dwBruijn, demonstrating successful blind TCP RST injection without requiring root privileges or TAP interfaces (PoC Write-up). The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. As of the time of reporting, there is no evidence of in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.00145 (0.145%), reflecting low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Attack complexity is rated High, as the attacker must be network-adjacent and know or guess the target port pair (Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target device running Cesanta Mongoose version 7.20 or earlier with the MIP built-in TCP/IP stack enabled (MG_ENABLE_TCPIP=1). Determine the listening port (e.g., port 8080 for HTTP) through network scanning.
  2. Observe active connection: Monitor network traffic (e.g., via ARP observation or passive sniffing) to identify an active TCP connection to the Mongoose device and determine the client's source port (e.g., 44444) and the server's destination port.
  3. Build the PoC: Clone the public PoC from https://github.com/dwBruijn/CVEs/blob/main/Mongoose/tcp_rst.md, place tcp_rst.c in the Mongoose source tree's poc/ directory, and compile: gcc -o tcp_rst tcp_rst.c ../mongoose.c -I.. -DMG_ENABLE_TCPIP=1 -lpthread.
  4. Craft forged RST packet: Construct a raw Ethernet + IPv4 + TCP frame with the RST flag set, using the correct port pair (sport=client port, dport=server port), an arbitrary source IP (different from the legitimate client), and an arbitrary sequence number (e.g., 99999999) outside the valid receive window.
  5. Inject the RST: Send the forged frame to the Mongoose MIP device. Because getpeer() matches only on ports, the connection is found; because rx_tcp() performs no sequence number or source IP validation, mg_error() is called and the connection is immediately terminated.
  6. Repeat for persistent DoS: Continuously inject RST packets to prevent any client from maintaining a TCP session. Leverage the predictable sequential ephemeral ports and deterministic ISNs to target subsequent connections without further observation (PoC Write-up).

Indicators of compromise

  • Network: Unexpected TCP RST packets arriving at a Mongoose MIP device with source IPs that do not match any known connected client; RST packets with sequence numbers far outside the expected receive window; high-frequency RST packets targeting the same port pair from varying source IPs.
  • Logs: Repeated MG_EV_ERROR events with the message "peer RST" in Mongoose application logs, especially when no legitimate client disconnection is expected; sudden connection termination events without corresponding client-side FIN or application-level close.
  • Process/Behavior: Mongoose-based services (HTTP server, MQTT broker, WebSocket endpoint) repeatedly dropping established connections and failing to maintain sessions; clients reporting unexpected disconnections with no application-layer error (PoC Write-up).

Mitigation and workarounds

The primary remediation is to upgrade Cesanta Mongoose to a version newer than 7.20, which should include fixes for source IP validation in getpeer() and sequence number window validation in rx_tcp(). Note that the vendor did not respond to the researcher's disclosure, so patch availability should be verified directly against the Cesanta Mongoose GitHub repository. As a workaround, network-level controls such as ingress filtering (BCP38) and restricting access to Mongoose MIP devices to trusted network segments can reduce the attack surface. Organizations should also consider disabling the MIP built-in TCP/IP stack if an OS-native TCP/IP stack is available, as the vulnerability is specific to the MIP stack (Red Hat Bugzilla, Red Hat Advisory).

Community reactions

The vulnerability was announced via the @CVEnew account on X (Twitter) shortly after publication (X/CVEnew). Red Hat tracked the issue via Bugzilla and assigned it medium priority/severity, indicating it affects packages in their ecosystem (Red Hat Bugzilla). Spain's INCIBE-CERT also published an early warning advisory. The vendor (Cesanta) did not respond to the researcher's disclosure, which was noted in the public write-up and CVE description. No significant broader media coverage or notable researcher commentary beyond the original disclosure has been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

swupdate

Affected

sid

swupdate: 2025.12+dfsg-10

Fixed

trixie

swupdate

Affected

Ubuntu

Unknown

devel

opencpn

Unknown

focal (esm-apps)

opencpn

Unknown

jammy

opencpn

Unknown

jammy (esm-apps)

opencpn

Unknown

noble

opencpn

Unknown

noble (esm-apps)

opencpn

Unknown

resolute

opencpn

Unknown

resolute (esm-apps)

opencpn

Unknown

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management