[Apollo] Advisories Statistics light light Login

RLSA-2026:78952

Security Mirrored from RHSA-2026:78952
Issued at: 2026-10-09
Updated at: 2026-10-09

Advisory content derived from Red Hat RHSA-2026:78952, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Moderate: tftp security update



Description

The Trivial File Transfer Protocol (TFTP) is typically used only for booting diskless workstations. The tftp packages include the tftp and tftp-server subpackages. The tftp subpackage provides the user interface for TFTP and the tftp-server subpackage provides the server. This allows users to transfer files to and from a remote machine.

Security Fix(es):

* tftp: tftp-hpa: Denial of Service due to out-of-bounds read/write in remap engine (CVE-2026-85234)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64

Fixes

2460997

CVEs

CVE-2026-85234

Affected packages

Rocky Linux 8 aarch64 - AppStream

tftp-0:5.2-28.el8_10.aarch64.rpm tftp-0:5.2-28.el8_10.src.rpm tftp-debuginfo-0:5.2-28.el8_10.aarch64.rpm tftp-debugsource-0:5.2-28.el8_10.aarch64.rpm tftp-server-0:5.2-28.el8_10.aarch64.rpm tftp-server-debuginfo-0:5.2-28.el8_10.aarch64.rpm

Rocky Linux 8 x86_64 - AppStream

tftp-0:5.2-28.el8_10.src.rpm tftp-0:5.2-28.el8_10.x86_64.rpm tftp-debuginfo-0:5.2-28.el8_10.x86_64.rpm tftp-debugsource-0:5.2-28.el8_10.x86_64.rpm tftp-server-0:5.2-28.el8_10.x86_64.rpm tftp-server-debuginfo-0:5.2-28.el8_10.x86_64.rpm