Stack-Based Buffer Overflow in rrdcached of rrdtool Affects Data Integrity
CVE-2026-43958
7.8HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 1 June 2026
What is CVE-2026-43958?
A vulnerability exists in rrdcached, a component of the rrdtool package, which can be exploited by a local attacker. By sending an oversized CREATE request to the rrdcached socket, the attacker may trigger a stack-based buffer overflow. This potentially allows for service disruption through a denial of service, or even more concerning, could lead to arbitrary code execution, putting the integrity and confidentiality of sensitive data at risk. It is essential for users of rrdtool to review their configurations and apply available patches to mitigate this risk.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.8.0-21.el10_2
Red Hat Enterprise Linux 8 0:1.7.0-17.el8_10
Red Hat Enterprise Linux 9 0:1.7.2-22.el9_8