EIP-2026-104518

PRE-CVE

NetBSD 5.0 - Hack GENOCIDE Environment Overflow (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104518. PoCs published by JMIT.

AI-analyzed exploit summary This exploit demonstrates a stack overflow vulnerability in the NetBSD 'hack' game (version 5.0 and below) via the GENOCIDED environment variable. It uses a Perl one-liner to generate a large payload of 'X' characters followed by a pattern to overwrite the return address, targeting the wizard mode of the game.

Description

NetBSD 5.0 - Hack GENOCIDE Environment Overflow (PoC)

Exploits (1)

exploitdb WORKING POC
by JMIT · bashdosnetbsd_x86
https://www.exploit-db.com/exploits/12652

This exploit demonstrates a stack overflow vulnerability in the NetBSD 'hack' game (version 5.0 and below) via the GENOCIDED environment variable. It uses a Perl one-liner to generate a large payload of 'X' characters followed by a pattern to overwrite the return address, targeting the wizard mode of the game.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: NetBSD hack game <= 5.0
No auth needed
Prerequisites: NetBSD 5.0 or below · Access to execute /usr/games/hack · Wizard mode enabled via -D flag
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026