CVE-2026-85234
Received Received - Intake

TFTP-HPA Inverse Remap Engine Out-of-Bounds Access

Vulnerability report for CVE-2026-85234, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: redhat-SADP

Description

A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a flaw in tftp-hpa where the in.tftpd remap engine mishandles inverse remap rules with non-empty error messages. This causes invalid match offsets to be passed to genmatchstring(), leading to out-of-bounds read/write operations. A remote attacker can exploit this by sending a crafted request to crash the daemon and cause a denial of service.

Impact Analysis

If exploited, this vulnerability could allow an attacker to crash the tftp-hpa daemon, disrupting file transfer services. This may lead to service unavailability and potential downtime for systems relying on TFTP for network booting or file transfers.

Mitigation Strategies

Update tftp-hpa to the latest patched version immediately to address the out-of-bounds read/write flaw. Disable the TFTP service if not required. Monitor network traffic for unusual requests targeting the TFTP daemon.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85234. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart