Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18743

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 2.5

Описание

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the poptConfigFileToString function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

Отчет

This Low impact heap overflow in popt occurs when processing specially crafted configuration files through an explicit call to poptConfigFileToString(). Red Hat products are less exposed as this function is not utilized by internal sources, limiting the attack surface to scenarios where untrusted popt configuration content is explicitly loaded.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10poptFix deferred
Red Hat Enterprise Linux 6poptFix deferred
Red Hat Enterprise Linux 7poptFix deferred
Red Hat Enterprise Linux 8poptFix deferred
Red Hat Enterprise Linux 9poptFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Hardened Imagespopt-main-1.19-11.1.hum1FixedRHSA-2026:5698419.08.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2510809popt-devel: popt-static: Short realloc in poptConfigFileToString

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

CVSS3: 2.5
nvd
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

msrc
19 дней назад

Popt-devel: popt-static: short realloc in poptconfigfiletostring

CVSS3: 2.5
debian
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to pro ...

CVSS3: 2.5
github
20 дней назад

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).

2.5 Low

CVSS3