Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-100693. PoCs published by Core Security.
AI-analyzed exploit summary This PoC exploits a remote buffer overflow in OpenBSD's ICMPv6 fragmentation handling to execute arbitrary shellcode (int 3) by overwriting the ext_free() function pointer on the mbuf. It uses raw sockets to send crafted packets, triggering the vulnerability.
Description
OpenBSD - ICMPv6 Fragment Remote Execution
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Core Security · pythonremotebsd
https://www.exploit-db.com/exploits/3491
This PoC exploits a remote buffer overflow in OpenBSD's ICMPv6 fragmentation handling to execute arbitrary shellcode (int 3) by overwriting the ext_free() function pointer on the mbuf. It uses raw sockets to send crafted packets, triggering the vulnerability.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
OpenBSD 4.0 CURRENT (GENERIC)
No auth needed
Prerequisites:
Raw socket support · PF_PACKET family support · Target system running vulnerable OpenBSD version
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026