Bug 2545290 (CVE-2026-103436) - CVE-2026-103436 apcupsd: apcupsd: Information disclosure via uninitialized stack buffer in CGI scripts
Summary: CVE-2026-103436 apcupsd: apcupsd: Information disclosure via uninitialized st...
Keywords:
Status: NEW
Alias: CVE-2026-103436
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2546310 2546311
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-02 16:31 UTC by OSIDB Bzimport
Modified: 2026-10-06 08:01 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-02 16:31:58 UTC
apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf("%*s %*s %s", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.


Note You need to log in before you can comment on or make changes to this bug.