Stack-Based Buffer Overflow in rrdcached of rrdtool Affects Data Integrity
CVE-2026-43958

7.8HIGH

What is CVE-2026-43958?

A vulnerability exists in rrdcached, a component of the rrdtool package, which can be exploited by a local attacker. By sending an oversized CREATE request to the rrdcached socket, the attacker may trigger a stack-based buffer overflow. This potentially allows for service disruption through a denial of service, or even more concerning, could lead to arbitrary code execution, putting the integrity and confidentiality of sensitive data at risk. It is essential for users of rrdtool to review their configurations and apply available patches to mitigate this risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.