CVE-2026-106026
Received Received - Intake

TFTP-HPA Out-of-Bounds Read in remap.c

Vulnerability report for CVE-2026-106026, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
H. Peter Anvin tftp-hpa 5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

tftp-hpa versions 5.4 before 6.0 have an out-of-bounds read flaw in the rewrite_string() function in tftpd/remap.c. This happens during jump label searches in heap memory. Attackers can send specially crafted read or write requests with filenames matching a remap jump rule to crash the in.tftpd process.

Detection Guidance

Check if your system runs tftp-hpa version 5.4 or earlier. Use commands like 'tftpd --version' or 'dpkg -l | grep tftp-hpa' to verify the installed version. Monitor network traffic for TFTP read/write requests with filenames matching remap jump rules.

Impact Analysis

Unauthenticated remote attackers could exploit this to crash the TFTP server, causing denial of service. The impact is limited to service disruption as no data is read or written beyond the crash.

Mitigation Strategies

Upgrade tftp-hpa to version 6.0 or later immediately. Disable TFTP service if not required. Restrict network access to TFTP ports (UDP 69) using firewalls. Monitor for unusual TFTP requests or crashes in the tftpd process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106026. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart