Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-18743

Опубликовано: 01 сент. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
poptunfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2510809

  • Crosses no security boundary

EPSS

Процентиль: 4%
0.00141
Низкий

Связанные уязвимости

CVSS3: 2.5
ubuntu
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

CVSS3: 2.5
redhat
около 2 месяцев назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

CVSS3: 2.5
nvd
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

msrc
19 дней назад

Popt-devel: popt-static: short realloc in poptconfigfiletostring

CVSS3: 2.5
github
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

EPSS

Процентиль: 4%
0.00141
Низкий