Description
A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Workaround
AI Analysis

Impact

The vulnerability resides in the tftp‑hpa server’s remap engine. When an inverse rule that aborts with a custom error message is processed, invalid match offsets can be passed to a string‑generation routine, leading to out‑of‑bounds read or write operations. This memory corruption causes the in a weakness is identified as CWE‑125. The impact is loss of availability for the affected tftp service, and no data or credential compromise occurs.

Affected Systems

The flaw affects tftp‑hpa deployments across Red Hat Enterprise Linux releases 10 through 9 as well as Red Hat Hardened Images. All systems running the in.tftpd daemon with the filename remapping feature enabled are susceptible.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score of < 1% indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog, meaning no known public exploits have been documented. A remote, unauthenticated attacker can trigger the failure by sending a specially crafted request to the tftp service over the network. The attack requires network access to the service; no special privileges or local access are necessary. If remapping is enabled, the engine may be forced to recompute match strings with invalid offsets, leading to memory corruption and service termination.

Generated by OpenCVE AI on September 20, 2026 at 14:28 UTC.

Remediation

Vendor Workaround

To mitigate this issue, avoid enabling filename remapping with the `m/-map-file` option for the `in.tftpd` service unless strictly necessary. If filename remapping is required, ensure that any inverse (`~`) and abort (`a`) rules in the remap file do not include a non-empty custom error message. Changes to the `in.tftpd` configuration may require restarting the service to take effect.


OpenCVE Recommended Actions

  • Disable the filename remapping option (`-map-file`) in the in.tftpd configuration if it is not essential.
  • If remapping must remain enabled, edit the remap file so that inverse (`~`) or abort (`a`) rules never specify a non‑empty custom error message.
  • Restart the in.tftpd service to apply any configuration changes.

Generated by OpenCVE AI on September 20, 2026 at 14:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service.
Title Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-125
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-15T19:43:52.914Z

Reserved: 2026-09-03T14:57:22.051Z

Link: CVE-2026-85234

cve-icon Vulnrichment

Updated: 2026-09-15T19:07:12.808Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:19:34.927

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-85234

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:36:00Z

Links: CVE-2026-85234 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses