Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41602

Опубликовано: 28 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

A flaw was found in the Apache Thrift TFramedTransport Go language implementation. This integer overflow or wraparound vulnerability could potentially allow an attacker to cause unexpected behavior or resource exhaustion, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat Ceph Storage 5rhceph/snmp-notifier-rhel8Out of support scope
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Out of support scope
Red Hat Ceph Storage 6rhceph/snmp-notifier-rhel9Out of support scope
Red Hat Ceph Storage 9rhceph/alloy-rhel10Out of support scope
Red Hat Ceph Storage 9rhceph/grafana-rhel10Out of support scope
Red Hat Ceph Storage 9rhceph/snmp-notifier-rhel10Out of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2463407github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVSS3: 7.5
nvd
3 месяца назад

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

msrc
3 месяца назад

Apache Thrift: Go TFramedTransport uint32 overflow

CVSS3: 7.5
debian
3 месяца назад

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedT ...

CVSS3: 7.5
github
3 месяца назад

Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability

7.5 High

CVSS3