Security Advisory

CVE-2026-50254

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-30 21:14:01
Last updated 2026-07-01 15:40:16
Assigner icscert
CVSS score 8.7
State PUBLISHED

Description

An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.