Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21004-1

Опубликовано: 22 июн. 2026
Источник: suse-cvrf

Описание

Security update for gsasl

This update for gsasl fixes the following issues:

Changes in gsasl:

  • CVE-2026-48829: DIGEST-MD5: Fix NULL pointer dereference in parser (bsc#1266371)

Список пакетов

openSUSE Leap 16.0
gsasl-2.2.1-160000.3.1
gsasl-devel-2.2.1-160000.3.1
gsasl-lang-2.2.1-160000.3.1
libgsasl18-2.2.1-160000.3.1

Описание

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.


Затронутые продукты
openSUSE Leap 16.0:gsasl-2.2.1-160000.3.1
openSUSE Leap 16.0:gsasl-devel-2.2.1-160000.3.1
openSUSE Leap 16.0:gsasl-lang-2.2.1-160000.3.1
openSUSE Leap 16.0:libgsasl18-2.2.1-160000.3.1

Ссылки