tftp-hpa 中发现了一个缺陷。当 的重映射(remap)引擎处理一条同时中止连接并附带非空自定义错误消息的逆向重映射规则时,它可能会将无效的匹配偏移量传递给 函数,从而导致越界读取或写入操作。远程未经身份验证的攻击者可以通过发送特制请求利用此漏洞,导致守护进程崩溃,进而引发拒绝服务(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Hardened Images | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85013 | 7.3 HIGH | Environment-modules: command injection in environment-modules bash completion via maliciou |
| CVE-2026-75092 | 7.3 HIGH | Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld |
| CVE-2026-81303 | 6.3 MEDIUM | Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam |
| CVE-2026-91786 | 6.1 MEDIUM | Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvali |
| CVE-2026-81320 | 5.5 MEDIUM | Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level |
| CVE-2026-79705 | 4.5 MEDIUM | Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outsi |
| CVE-2026-79699 | 4.4 MEDIUM | Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacem |
| CVE-2026-91926 | 3.7 LOW | Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair en |
No comments yet