Sceawere
Vulnerability Detail
CVE-2026-106026UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
tftp-hpa OOB Read Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 11h ago
- Vendor
- H. Peter Anvin
- Product
- tftp-hpa
- Attack Type
- Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-10-06T14:17:42.083Z",
"pubdate": "2026-10-06T14:17:42.083Z",
"executiveSummary": "This vulnerability is an out-of-bounds (OOB) read identified in tftp-hpa versions prior to 6.0, specifically located within the remap rule processing logic.\nThe vulnerability occurs in the rewrite_string() function within tftpd/remap.c. An unauthenticated remote attacker can exploit this flaw by sending specifically crafted read or write requests.\nThe impact is a denial-of-service (DoS) condition; successful exploitation causes the forked in.tftpd request handler process to crash when processing filename strings against configured remap jump rules.\nThe vulnerability resides in the way the application traverses heap memory during the execution of jump label searches, leading to memory access violations.\nThis issue represents a significant risk to service availability for systems relying on tftp-hpa for file transfers, as no prior authentication is required to trigger the crash.\nAttackers can trigger the vulnerability remotely over the network by supplying a malicious filename that interacts with the remap configuration, forcing the server process into an invalid state.",
"technicalDetails": "The root cause of this vulnerability is an out-of-bounds read error occurring during the execution of the rewrite_string() function in tftpd/remap.c. When the tftp-hpa server is configured with remap rules, it performs string matching and replacement on requested filenames to facilitate file path remapping.\nThe vulnerability manifests during the search process for jump labels within these remap rules. The implementation of the parser fails to adequately validate boundary conditions while iterating through memory addresses associated with the rule strings.\nSpecifically, as the function iterates through the heap memory to locate or process jump labels, it can extend beyond the allocated buffer boundaries if the input filename string is crafted in a manner that misleads the parser logic.\nThe attack flow proceeds as follows: 1) The attacker initiates an unauthenticated TFTP read or write request to the in.tftpd daemon. 2) The request contains a filename specifically crafted to match or trigger a complex remap jump rule defined in the server configuration. 3) The server invokes rewrite_string() to parse and apply the remap transformation. 4) Inside rewrite_string(), the pointer arithmetic performed during the jump label search results in an out-of-bounds read access. 5) This invalid memory access triggers a segmentation fault or memory protection exception within the forked child process, causing the in.tftpd request handler to crash immediately.\nThe vulnerable component is the remapping engine of the tftpd daemon. Affected versions include all releases of tftp-hpa prior to 6.0. The vulnerability is network-exposed, requiring only connectivity to the TFTP service port (typically UDP 69). No authentication is required to interact with the service, and no special privileges are needed to send the malicious request, making the service highly susceptible to remote DoS attacks. Because the flaw occurs in the forked process, the main listener process may remain active, allowing for repeated exploitation attempts to exhaust service availability."
}