---
id: CVE-2026-106026
title: >-
  tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in
  rewrite_string() in tftpd/remap.c that walks heap memory during jump label
  searches
summary: >-
  tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in
  rewrite_string() in tftpd/remap.c that walks heap memory during jump label
  searches. Unauthenticated remote attackers can send read or write requests
  whose filename …
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-125
vendor: H. Peter Anvin
product: tftp-hpa
affected:
  - tftp-hpa >= 5.4 < 6.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T14:17:42.083'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106026'
references:
  - url: 'https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/'
    label: disclosure@vulncheck.com
  - url: >-
      https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf9829836b3d06f14291
    label: disclosure@vulncheck.com
  - url: >-
      https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/tree/tftpd/remap.c?h=tftp-hpa-5.4#n762
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tftp-hpa-5.4-before-6.0-out-of-bounds-read-via-tftpd-remap-jump-rule
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T14:00:19.150Z'
---

## Overview

tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send read or write requests whose filename matches a remap jump rule to crash the forked in.tftpd request handler.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
