Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89478.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-89478
Upstream
  • CVE-2026-43958
Published
2026-06-01T19:16:47Z
Modified
2026-09-04T05:27:10Z
Summary
CVE-2026-43958 affecting package rrdtool for versions less than 1.8.0-3
Details

A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.

References

Affected packages

Azure Linux:3 / rrdtool

Package

Name
rrdtool
Purl
pkg:rpm/azure-linux/rrdtool

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89478.json"