Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58023

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in Apache Thrift c_glib bindings. This out-of-bounds read vulnerability allows an attacker to potentially access sensitive information or cause a denial of service. The vulnerability occurs when the software attempts to read data beyond the allocated memory buffer.

Отчет

This Moderate severity out-of-bounds read vulnerability in Apache Thrift c_glib bindings could lead to information disclosure and denial of service. Red Hat products such as OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are affected where they utilize vulnerable versions of Apache Thrift. Red Hat Enterprise Linux AI is not affected as the vulnerable code is not present.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3thriftNot affected
Red Hat OpenShift Container Platform 4conmon-rsFix deferred
Red Hat OpenShift Container Platform 4kata-containersFix deferred
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2507440thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read

EPSS

Процентиль: 62%
0.01083
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
8 дней назад

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 9.1
nvd
8 дней назад

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 9.1
debian
8 дней назад

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. Th ...

CVSS3: 9.1
github
8 дней назад

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 62%
0.01083
Низкий

6.5 Medium

CVSS3