Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55969

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

A flaw was found in Apache Thrift's C++, c_glib, Go, netstd, Delphi, and Haxe bindings. This integer overflow or wraparound vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted input. The flaw can lead to the affected service becoming unavailable.

Отчет

This vulnerability in Apache Thrift bindings, rated as Important, allows a remote attacker to trigger a denial of service. The integer overflow or wraparound flaw can lead to affected services becoming unavailable, impacting the reliability of systems utilizing vulnerable Thrift components across Red Hat products such as OpenShift Container Platform and Red Hat Ceph Storage.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Will not fix
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Will not fix
Red Hat AI Inference Serverrhaii/vllm-spyre-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-tpu-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2507433thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound

EPSS

Процентиль: 49%
0.00645
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
nvd
около 2 месяцев назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
msrc
около 1 месяца назад

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()

CVSS3: 7.5
debian
около 2 месяцев назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...

CVSS3: 7.5
github
около 2 месяцев назад

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 49%
0.00645
Низкий

7.5 High

CVSS3