<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2026-88779 on Martin's Blog</title><link>https://mac.sploit.dk/tags/cve-2026-88779/</link><description>Recent content in CVE-2026-88779 on Martin's Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 05 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://mac.sploit.dk/tags/cve-2026-88779/index.xml" rel="self" type="application/rss+xml"/><item><title>Finding the NetScaler SAML Crash in nsaaad</title><link>https://mac.sploit.dk/blog/netscaler-saml-prefixlist-nsaaad-crash/</link><pubDate>Sat, 03 Oct 2026 14:33:25 +0200</pubDate><guid>https://mac.sploit.dk/blog/netscaler-saml-prefixlist-nsaaad-crash/</guid><description>&lt;p&gt;NetScaler&amp;rsquo;s SAML problem led me into &lt;code&gt;nsaaad&lt;/code&gt;, the authentication daemon. In build 14.1-73.30, a routine identified by embedded source strings as &lt;code&gt;canonicalize_data&lt;/code&gt; puts namespace-prefix pointers into a sixteen-entry stack array. It accepts sixteen entries, but the code that consumes them expects a NULL terminator. There is no room for that terminator when the array is full.&lt;/p&gt;&#10;&lt;p&gt;The next pointer read comes from the saved stack canary. The diagnostic code treats it as a string pointer, and the controlled test ended in &lt;code&gt;strlen&lt;/code&gt; with &lt;code&gt;SIGBUS&lt;/code&gt;, a core, and one Pitboss restart of &lt;code&gt;nsaaad&lt;/code&gt;.&lt;/p&gt;&#10;&lt;p&gt;That test started at the daemon&amp;rsquo;s internal message boundary. The disposable appliance had no AAA licence, so I could not reproduce delivery through a network-facing Gateway or AAA SAML virtual server. The static path reaches the same operation, but the external route remains untested locally. The observed impact is one daemon crash and restart; the run did not establish code execution, restart exhaustion, or an appliance reboot.&lt;/p&gt;</description></item></channel></rss>