EIP-2026-103006

PRE-CVE

Socat 1.7.3.4 - Heap-Based Overflow (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103006. PoCs published by hieubl.

AI-analyzed exploit summary This PoC demonstrates a heap-based overflow in Socat 1.7.3.4 due to an integer overflow in the `_socat()` function, where a large buffer size (0x8000000000000050) causes an incorrect malloc allocation, leading to a crash. The lack of PIE mitigation in the binary exacerbates the exploitability.

Description

Socat 1.7.3.4 - Heap-Based Overflow (PoC)

Exploits (1)

exploitdb WORKING POC
by hieubl · textlocallinux
https://www.exploit-db.com/exploits/47999

This PoC demonstrates a heap-based overflow in Socat 1.7.3.4 due to an integer overflow in the `_socat()` function, where a large buffer size (0x8000000000000050) causes an incorrect malloc allocation, leading to a crash. The lack of PIE mitigation in the binary exacerbates the exploitability.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Socat 1.7.3.4
No auth needed
Prerequisites: Socat 1.7.3.4 compiled without PIE · Ability to execute socat with crafted arguments
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026