Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18785

Опубликовано: 04 авг. 2026
Источник: redhat

Описание

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability.

A flaw was found in open62541. A local attacker can exploit a use-after-free vulnerability in the UA_Client_getRemoteDataTypes function by performing a specific manipulation. This could potentially lead to limited information disclosure, data corruption, or a Denial of Service (DoS).

Отчет

This Moderate severity use-after-free flaw in open62541 allows a local attacker to trigger a crash or potentially corrupt data through specific manipulation of the UA_Client_getRemoteDataTypes function. While publicly disclosed, exploitation requires local access and specific conditions, limiting its broader impact on typical Red Hat deployments.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2511141open62541: open62541: Use-after-free vulnerability via local manipulation

Связанные уязвимости

CVSS3: 5.3
ubuntu
12 дней назад

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability.

CVSS3: 5.3
nvd
12 дней назад

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability.

CVSS3: 5.3
debian
12 дней назад

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4 ...

CVSS3: 5.3
github
12 дней назад

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability.