{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/sonic-3-a.i.r./feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-66733"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sonic 3 A.I.R."],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eSonic 3 A.I.R. (Angel Island Revisited) contains a memory exhaustion vulnerability (CVE-2026-66733) located within the \u003ccode\u003eReceivedPacketCache::enqueuePacket()\u003c/code\u003e function. The flaw stems from a lack of bounds checking on the \u003ccode\u003emUniquePacketID\u003c/code\u003e field parsed from incoming UDP packets. An unauthenticated remote attacker can exploit this by crafting a UDP packet containing the maximum possible uint32 value for the \u003ccode\u003emUniquePacketID\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eUpon receipt, the application attempts to allocate a \u003ccode\u003eCacheItem\u003c/code\u003e object for every packet ID gap between the current state and the provided maximum ID. This results in an uncontrolled memory allocation sequence that exhausts the available host system memory. The process fails to handle the resulting \u003ccode\u003estd::bad_alloc\u003c/code\u003e exception, which propagates to \u003ccode\u003estd::terminate()\u003c/code\u003e, causing an immediate server process crash. This vulnerability impacts all deployments of the application before commit 2492d18, affecting Windows, Linux, and macOS environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service condition for the targeted Sonic 3 A.I.R. instance. As the crash is triggered by an uncaught exception, the server process will cease functioning, requiring a manual restart by an administrator. This vulnerability poses a significant risk to publicly accessible instances, as it requires no authentication to execute, allowing any remote user to crash the service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Sonic 3 A.I.R. to commit 2492d18 or later immediately to apply the patch for CVE-2026-66733.\u003c/li\u003e\n\u003cli\u003eIf updating is not immediately possible, restrict network access to the UDP port used by the server to trusted IP addresses only, using host-based firewalls or network access control lists.\u003c/li\u003e\n\u003cli\u003eMonitor system memory usage on the host running the server process; sudden, abnormal spikes in memory consumption associated with the process may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T13:24:19Z","date_published":"2026-08-06T13:24:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sonic-3-air-memory-exhaustion/","summary":"Sonic 3 A.I.R. versions before commit 2492d18 are vulnerable to a remote denial-of-service attack due to improper bounds checking on UDP packet IDs, leading to memory exhaustion and server crashes.","title":"Unbounded Memory Allocation Vulnerability in Sonic 3 A.I.R.","url":"https://feed.craftedsignal.io/briefs/2026-08-sonic-3-air-memory-exhaustion/"}],"language":"en","title":"CraftedSignal Threat Feed - Sonic 3 A.I.R.","version":"https://jsonfeed.org/version/1.1"}