Описание
Security update for rrdtool
This update for rrdtool fixes the following issue:
- CVE-2026-43958: stack buffer overflow in
rrdcachedhandle_request_create()can lead to local privilege escalation via unbounded DS/RRA arguments (bsc#1267243).
Список пакетов
openSUSE Leap 16.0
librrd8-1.9.0-160000.4.1
lua-rrdtool-1.9.0-160000.4.1
perl-rrdtool-1.9.0-160000.4.1
python3-rrdtool-1.9.0-160000.4.1
rrdtool-1.9.0-160000.4.1
rrdtool-cached-1.9.0-160000.4.1
rrdtool-devel-1.9.0-160000.4.1
rrdtool-doc-1.9.0-160000.4.1
ruby-rrdtool-1.9.0-160000.4.1
tcl-rrdtool-1.9.0-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1267243
- SUSE CVE CVE-2026-43958 page
Описание
A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.
Затронутые продукты
openSUSE Leap 16.0:librrd8-1.9.0-160000.4.1
openSUSE Leap 16.0:lua-rrdtool-1.9.0-160000.4.1
openSUSE Leap 16.0:perl-rrdtool-1.9.0-160000.4.1
openSUSE Leap 16.0:python3-rrdtool-1.9.0-160000.4.1
Ссылки
- CVE-2026-43958
- SUSE Bug 1267243