[ALSA-2026:78952] Moderate: tftp security update
Type:
security
Severity:
moderate
Release date:
2026-10-09
Description:
The Trivial File Transfer Protocol (TFTP) is typically used only for booting diskless workstations. The tftp packages include the tftp and tftp-server subpackages. The tftp subpackage provides the user interface for TFTP and the tftp-server subpackage provides the server. This allows users to transfer files to and from a remote machine. Security Fix(es): * tftp: tftp-hpa: Denial of Service due to out-of-bounds read/write in remap engine (CVE-2026-85234) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 tftp-5.2-28.el8_10.aarch64.rpm 2587efa6144e89eddf3fff9ad731989cde33d3b2cf1b14d7f144ea9764661d23
aarch64 tftp-server-5.2-28.el8_10.aarch64.rpm 9178e219000eda01fb696c701bbcb5541701c95a8c4a57734b97f1c3f55be944
ppc64le tftp-server-5.2-28.el8_10.ppc64le.rpm c80347929bc4f8c4018e38e40f4f67eca15fa9ea289a744bf81df481dbdc4b4b
ppc64le tftp-5.2-28.el8_10.ppc64le.rpm ff4dd716cfda69263e4793474970f961d43080fc23fd7a606a143f4574b5fb87
s390x tftp-server-5.2-28.el8_10.s390x.rpm 1ec2535e856b652031f59fea3a434228f8959e1227d9feb3b94c04380f13f791
s390x tftp-5.2-28.el8_10.s390x.rpm 503b082e42f5cff103142ead053be15a503f1e798f885eb61c69880a7772d47b
x86_64 tftp-5.2-28.el8_10.x86_64.rpm ca1bab3c68acf7c06ba5b30b32b6e494347e7112ed2f7c24a2370b2ec9cbf4cb
x86_64 tftp-server-5.2-28.el8_10.x86_64.rpm fe98a7f2501448e426a041ed52c052cbde0ad22778cd9cd3dc54e0776af0db59
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.