Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55970

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in Apache Thrift C++ bindings. This buffer over-read vulnerability allows a remote attacker to read beyond the intended memory boundaries. This could lead to the disclosure of sensitive information or cause the application to become unavailable.

Отчет

This Moderate impact vulnerability in Apache Thrift C++ bindings could lead to information disclosure due to a buffer over-read. Red Hat products utilizing affected versions of Apache Thrift, such as Red Hat Enterprise Linux AI, OpenShift Container Platform, and Red Hat OpenShift AI, may be susceptible if processing untrusted data with Thrift client applications.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2507438thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability

EPSS

Процентиль: 54%
0.00825
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
8 дней назад

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 6.5
nvd
8 дней назад

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 6.5
debian
8 дней назад

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This is ...

CVSS3: 6.5
github
8 дней назад

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 54%
0.00825
Низкий

6.5 Medium

CVSS3