MEDIUM 6.3 NVD
CVE-2026-106026
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Una
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.
References
- https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/
- https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf
- https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/tree/tftpd/remap.c?h=tftp-hpa-5.4
- https://www.vulncheck.com/advisories/tftp-hpa-5.4-before-6.0-out-of-bounds-read-via-tftpd-
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-10-06 via NVD.
vulnfeed aggregates 9311 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.