CVE-2026-106026: H. Peter Anvin Tftp-Hpa
Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.
tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.
Affected products
- H. Peter Anvin Tftp-Hpa: from 5.4, before 6.0 (fixed in 6.0)
Published 2026-10-06. Last modified 2026-10-06.