Unsafe Deserialization Vulnerability in sblim-sfcb Affects Red Hat Products
CVE-2026-73583

6.6MEDIUM

What is CVE-2026-73583?

A significant flaw has been identified in sblim-sfcb, allowing local attackers to exploit an unsafe deserialization vulnerability within the provider-manager's inter-process communication (IPC) message parsing. By transmitting a specially crafted IPC message, an attacker may trigger out-of-bounds memory access, potentially leading to the termination of the provider-manager process. This exploitation could result in a denial of service and may also permit limited unintended information disclosure, affecting the integrity and availability of the system.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.