Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70368

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".

Отчет

This Moderate impact vulnerability affects stunnel services if their configuration allows long attacker-controlled log messages. Server-side IMAP protocol negotiation ("protocol = imap") is known to be affected, where a remote, unauthenticated attacker can trigger a denial-of-service by sending an oversized IMAP command. Reliable integrity impact or code execution as a result of this issue would be very difficult and likely impractical. This issue specifically affects "stunnel" 5.79 and lower when exposed to untrusted networks.

Меры по смягчению последствий

To mitigate this issue, avoid exposing stunnel services to untrusted clients. Restrict access to these services to trusted networks only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10stunnelFix deferred
Red Hat Enterprise Linux 6stunnelNot affected
Red Hat Enterprise Linux 7stunnelNot affected
Red Hat Enterprise Linux 8stunnelFix deferred
Red Hat Enterprise Linux 9stunnelFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2462029stunnel: Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message

EPSS

Процентиль: 28%
0.00353
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
27 дней назад

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".

CVSS3: 6.5
nvd
27 дней назад

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".

msrc
25 дней назад

Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message

CVSS3: 6.5
debian
27 дней назад

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" ...

CVSS3: 6.5
github
27 дней назад

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".

EPSS

Процентиль: 28%
0.00353
Низкий

6.5 Medium

CVSS3