Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18739

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 2.5
EPSS Низкий

Описание

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

Отчет

This flaw has Low impact as it requires a host application to repeatedly call poptStuffArgs or use deep alias nesting, leading to an off-by-one error. Exploitation is only possible if the host application then unsafely processes the corrupted poptContext data, such as sinking it into exec, system, popen, or dlopen.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10poptAffected
Red Hat Enterprise Linux 6poptOut of support scope
Red Hat Enterprise Linux 7poptFix deferred
Red Hat Enterprise Linux 8poptFix deferred
Red Hat Enterprise Linux 9poptFix deferred
Red Hat Hardened ImagespoptAffected
Red Hat OpenShift Container Platform 4rhcosUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2510737popt-devel: popt-static: Off-by-one in poptStuffArgs

EPSS

Процентиль: 1%
0.00095
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
6 дней назад

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

CVSS3: 2.5
nvd
6 дней назад

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

msrc
3 дня назад

Popt-devel: popt-static: off-by-one in poptstuffargs

CVSS3: 2.5
debian
6 дней назад

A flaw was found in popt, a command-line option parsing library. An of ...

CVSS3: 2.5
github
6 дней назад

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

EPSS

Процентиль: 1%
0.00095
Низкий

2.5 Low

CVSS3