Out-of-Bounds Read Vulnerability in tftp-hpa Versions by the Vendor
CVE-2026-106026

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106026?

The tftp-hpa 5.4 version prior to 6.0 contains a vulnerability in the rewrite_string() function located in tftpd/remap.c, which can lead to out-of-bounds reads. This occurs when an unauthenticated remote attacker exploits jump label searches on heap memory, potentially allowing them to crash the forked in.tftpd request handler by sending specific read or write requests matching a remap jump rule. It is crucial to update to the latest version to protect against this exposure.

Affected Version(s)

tftp-hpa 5.4 < 6.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.