Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-18743

Опубликовано: 02 сент. 2026
Источник: msrc
CVSS3: 2.5
EPSS Низкий

Описание

Popt-devel: popt-static: short realloc in poptconfigfiletostring

Обновления

ПродуктСтатьяОбновление
azl3 popt 1.19-1 on Azure Linux 3.0
azl3 rsync 3.4.3-1 on Azure Linux 3.0
azl3 rsync 3.5.0-1 on Azure Linux 3.0

Показывать по

EPSS

Процентиль: 4%
0.00141
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

CVSS3: 2.5
redhat
около 2 месяцев назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

CVSS3: 2.5
nvd
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

CVSS3: 2.5
debian
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to pro ...

CVSS3: 2.5
github
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

EPSS

Процентиль: 4%
0.00141
Низкий

2.5 Low

CVSS3