GHSA-w9pp-27r4-r6rjMediumCVSS 3.7
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd...
🔗 CVE IDs covered (1)
📋 Description
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-106026
- https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git
- https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf9829836b3d06f14291
- https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/tree/tftpd/remap.c?h=tftp-hpa-5.4#n762
- https://www.vulncheck.com/advisories/tftp-hpa-5.4-before-6.0-out-of-bounds-read-via-tftpd-remap-jump-rule
- https://github.com/advisories/GHSA-w9pp-27r4-r6rj