Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41907

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

A flaw was found in uuid. The library's versions v3, v5, and v6 do not adequately check the size of external memory buffers provided by applications. This oversight allows the library to write data beyond the designated buffer limits without signaling an error. Such out-of-bounds writes can lead to data corruption, unintended information disclosure, or disrupt application availability.

Отчет

This is a Moderate impact flaw. The uuid library, as used in Red Hat products, is susceptible to out-of-bounds writes when applications provide undersized external buffers for UUID generation. This can lead to data corruption or unintended information disclosure within the context of the vulnerable application, but requires specific application misuse of the library's API.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-pccsFix deferred
Cryostat 4cryostat-openshift-console-plugin-npmFix deferred
Cryostat 4uuidFix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleFix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorFix deferred
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2461639uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality

EPSS

Процентиль: 26%
0.00337
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

CVSS3: 7.5
nvd
3 месяца назад

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

msrc
3 месяца назад

uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided

CVSS3: 7.5
debian
3 месяца назад

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to ...

CVSS3: 7.5
github
4 месяца назад

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

EPSS

Процентиль: 26%
0.00337
Низкий

4.8 Medium

CVSS3