CVE-2026-16172
Received Received - Intake

Out-of-Bounds Heap Read in Netskope Client EPDLP Service

Vulnerability report for CVE-2026-16172, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Netskope

Description

Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could potentially crash the EPDLP service, temporarily interrupting DLP enforcement. A successful exploit could potentially also reveal per-boot memory layout information to unauthorized users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netskope endpoint_dlp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds heap read vulnerability in Netskope's Endpoint DLP (EPDLP) service. A local standard user could send a specially crafted message that isn't properly validated, potentially crashing the kernel driver handler. This might crash the EPDLP service, temporarily stopping DLP enforcement and revealing per-boot memory layout information.

Detection Guidance

This vulnerability involves an out-of-bounds heap read in the Netskope Endpoint DLP service. Detection requires monitoring for crashes in the EPDLP service or kernel driver handler. Check system logs for kernel driver crashes or EPDLP service interruptions. Use commands like 'dmesg' or 'journalctl -k' to review kernel logs for crashes. Monitor Netskope client logs for service failures.

Impact Analysis

The impact includes temporary interruption of data loss prevention (DLP) enforcement on affected systems, causing potential data exposure risks. It may also allow unauthorized users to access memory layout details, which could aid further attacks.

Compliance Impact

This vulnerability could temporarily interrupt DLP enforcement, potentially leading to unauthorized data exposure. This may impact compliance with GDPR or HIPAA by failing to protect sensitive data during enforcement gaps.

Mitigation Strategies

Apply the latest security patches from Netskope to fix the out-of-bounds read issue. Temporarily disable the EPDLP service if a patch is unavailable, but note this will interrupt DLP enforcement. Restrict local user access to prevent exploitation attempts. Monitor for unusual activity or crashes in the EPDLP service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16172. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart