Out-of-Bounds Read Vulnerability in tftp-hpa Versions by the Vendor
CVE-2026-106026
6.3MEDIUM
What is CVE-2026-106026?
The tftp-hpa 5.4 version prior to 6.0 contains a vulnerability in the rewrite_string() function located in tftpd/remap.c, which can lead to out-of-bounds reads. This occurs when an unauthenticated remote attacker exploits jump label searches on heap memory, potentially allowing them to crash the forked in.tftpd request handler by sending specific read or write requests matching a remap jump rule. It is crucial to update to the latest version to protect against this exposure.
Affected Version(s)
tftp-hpa 5.4 < 6.0
