CVE-2026-19874
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game design limits matches to a maximum of 16 players, and the corresponding buffer for storing kicked player IDs is sized accordingly. If "kick_num" exceeds this limit, the function continues writing the provided player IDs past the end of the intended buffer and into adjacent memory regions.
1 article across 1 outlet · first covered Aug 24, 2026 · latest Aug 24, 2026
Coverage timeline
-
CVE-2026-19874: Metal Gear Online 3 RCE Flawsecurityonline.info · Aug 24, 2026