Impact
The vulnerability resides in the tftp‑hpa server’s remap engine. When an inverse rule that aborts with a custom error message is processed, invalid match offsets can be passed to a string‑generation routine, leading to out‑of‑bounds read or write operations. This memory corruption causes the in a weakness is identified as CWE‑125. The impact is loss of availability for the affected tftp service, and no data or credential compromise occurs.
Affected Systems
The flaw affects tftp‑hpa deployments across Red Hat Enterprise Linux releases 10 through 9 as well as Red Hat Hardened Images. All systems running the in.tftpd daemon with the filename remapping feature enabled are susceptible.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score of < 1% indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog, meaning no known public exploits have been documented. A remote, unauthenticated attacker can trigger the failure by sending a specially crafted request to the tftp service over the network. The attack requires network access to the service; no special privileges or local access are necessary. If remapping is enabled, the engine may be forced to recompute match strings with invalid offsets, leading to memory corruption and service termination.
OpenCVE Enrichment