Описание
Security update for gsasl
This update for gsasl fixes the following issues:
Changes in gsasl:
- CVE-2026-48829: DIGEST-MD5: Fix NULL pointer dereference in parser (bsc#1266371)
Список пакетов
openSUSE Leap 16.0
gsasl-2.2.1-160000.3.1
gsasl-devel-2.2.1-160000.3.1
gsasl-lang-2.2.1-160000.3.1
libgsasl18-2.2.1-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1266371
- SUSE CVE CVE-2026-48829 page
Описание
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
Затронутые продукты
openSUSE Leap 16.0:gsasl-2.2.1-160000.3.1
openSUSE Leap 16.0:gsasl-devel-2.2.1-160000.3.1
openSUSE Leap 16.0:gsasl-lang-2.2.1-160000.3.1
openSUSE Leap 16.0:libgsasl18-2.2.1-160000.3.1
Ссылки
- CVE-2026-48829
- SUSE Bug 1266371