Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43958

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.

Отчет

This stack buffer overflow in rrdcached allows a local attacker with socket access to cause a denial of service or potentially execute arbitrary code. The default configuration exposes rrdcached via a local UNIX socket, requiring local access and specific permissions for exploitation. Deployments exposing TCP listeners without proper access controls face a higher risk. The Red Hat Product Security team has rated this vulnerability as having a Moderate severity, this is due to the fact of the attack vector is local and the attacker needs permission to reach out to the UNIX socket in order to exploit this flaw.

Меры по смягчению последствий

Restrict access to the rrdcached UNIX socket using filesystem permissions and group ownership to prevent untrusted local users from connecting. Avoid exposing rrdcached on TCP listeners unless strictly necessary, and ensure any such listeners are protected by network access controls. Additionally, run the rrdcached daemon as an unprivileged user and group using the -U and -G options to minimize impact in case of compromise. If rrdcached is restarted or reloaded, these configurations will be reapplied.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rrdtoolWill not fix
Red Hat Enterprise Linux 7rrdtoolAffected
Red Hat Enterprise Linux 10rrdtoolFixedRHSA-2026:3373130.06.2026
Red Hat Enterprise Linux 8rrdtoolFixedRHSA-2026:3415501.07.2026
Red Hat Enterprise Linux 9rrdtoolFixedRHSA-2026:3415601.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2460932rrdtool: rrdtool: Stack buffer overflow allows local code execution or denial of service

EPSS

Процентиль: 3%
0.00132
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.

CVSS3: 7.8
nvd
2 месяца назад

A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.

CVSS3: 7.8
msrc
около 2 месяцев назад

Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service

CVSS3: 7.8
debian
2 месяца назад

A flaw was found in rrdcached, a component of rrdtool. A local attacke ...

rocky
27 дней назад

Moderate: rrdtool security update

EPSS

Процентиль: 3%
0.00132
Низкий

7.8 High

CVSS3