Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73583

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.

Отчет

This vulnerability has a Moderate impact. A local attacker with access to a system running sblim-sfcb can exploit an unsafe deserialization flaw in the provider-manager IPC message parsing. This can lead to out-of-bounds access and process termination, resulting in a denial of service. Exploitation depends on local IPC configuration and socket permissions, limiting its broader impact.

Меры по смягчению последствий

To mitigate this issue, restrict access to the local connect socket used by sblim-sfcb to prevent untrusted local users from obtaining the internal provider-manager descriptor. Deployments where only trusted users can reach this socket will have materially reduced exposure. Consult your system's documentation for appropriate methods to secure local IPC channels and socket permissions for the sblim-sfcb service. A restart of the sfcbd service may be required for changes to take effect, which could temporarily disrupt services relying on sblim-sfcb.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sblim-sfcbFix deferred
Red Hat Enterprise Linux 6sblim-sfcbOut of support scope
Red Hat Enterprise Linux 7sblim-sfcbFix deferred
Red Hat Enterprise Linux 8sblim-sfcbFix deferred
Red Hat Enterprise Linux 9sblim-sfcbFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2462126sblim-sfcb: Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr

EPSS

Процентиль: 1%
0.00092
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
16 дней назад

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.

CVSS3: 6.6
nvd
16 дней назад

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.

CVSS3: 6.6
github
16 дней назад

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.

EPSS

Процентиль: 1%
0.00092
Низкий

6.6 Medium

CVSS3