CVE-2026-43958 Details
Description
A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.
A stack-based buffer overflow vulnerability has been identified in rrdcached, a component of rrdtool, versions through 1.8.0-20.el10. This vulnerability allows local attackers with access to a rrdcached socket to exploit the issue by sending oversized CREATE requests. The flaw can cause a denial-of-service by crashing the daemon or potentially lead to arbitrary code execution, thereby affecting the integrity and confidentiality of data.
Restrict access to the rrdcached UNIX socket using filesystem permissions and group ownership to prevent untrusted local users from connecting. Avoid exposing rrdcached on TCP listeners unless strictly necessary, and ensure any such listeners are protected by network access controls. Run the rrdcached daemon as an unprivileged user and group to minimize impact in case of compromise.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |