Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-68767

Опубликовано: 22 авг. 2026
Источник: debian

Описание

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hashcatunfixedpackage

Примечания

  • https://github.com/hashcat/hashcat/issues/4739

  • https://github.com/hashcat/hashcat/pull/4750

  • Fixed by: https://github.com/hashcat/hashcat/commit/93b55d37d3b2340013d4036f10181ddc67d44249

  • Crash in CLI tool, no security impact

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 дней назад

(hashcat's fgetl() function in src/filehandling.c writes a null termina ...)

CVSS3: 6.1
nvd
9 дней назад

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.

CVSS3: 6.1
github
9 дней назад

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.