CVE-2026-106026
tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.
| CWE | CWE-125 |
| Vendor | h. peter anvin |
| Product | tftp-hpa |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for h. peter anvin tftp-hpa
Be the first to know when new low vulnerabilities affecting h. peter anvin tftp-hpa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected Versions
H. Peter Anvin / tftp-hpa
5.4 < 6.0
References
git.kernel.org: https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf9829836b3d06f14291 git.kernel.org: https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/tree/tftpd/remap.c?h=tftp-hpa-5.4#n762 git.kernel.org: https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/ vulncheck.com: https://www.vulncheck.com/advisories/tftp-hpa-5.4-before-6.0-out-of-bounds-read-via-tftpd-remap-jump-rule
Credits
Tristan Madani