CVE-2026-106026

NameCVE-2026-106026
Descriptiontftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability i ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tftp-hpa (PTS)bookworm5.2+20150808-1.4vulnerable
trixie5.2+20240610-3vulnerable
forky5.4-2vulnerable
sid7.2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tftp-hpasource(unstable)7.1-1

Notes

https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf9829836b3d06f14291 (tftp-hpa-6.0)

Search for package or bug name: Reporting problems