Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55969

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Apache Thrift's C++, c_glib, Go, netstd, Delphi, and Haxe bindings. This integer overflow or wraparound vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted input. The flaw can lead to the affected service becoming unavailable.

Отчет

This vulnerability in Apache Thrift bindings, rated as Important, allows a remote attacker to trigger a denial of service. The integer overflow or wraparound flaw can lead to affected services becoming unavailable, impacting the reliability of systems utilizing vulnerable Thrift components across Red Hat products such as OpenShift Container Platform and Red Hat Ceph Storage.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Affected
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2507433thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound

EPSS

Процентиль: 62%
0.01097
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
nvd
8 дней назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
debian
8 дней назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...

CVSS3: 7.5
github
8 дней назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 62%
0.01097
Низкий

7.5 High

CVSS3