Remote Null Pointer Dereference in Trusted Domain Project OpenARC
CVE-2026-100895
Key Information:
- Vendor
Trusted Domain Project
- Status
- Vendor
- CVE Published:
- 28 September 2026
Badges
What is CVE-2026-100895?
A vulnerability in Trusted Domain Project OpenARC has been identified in the arc_parse_canon_t function within the libopenarc/arc-canon.c library, specifically impacting versions up to 1.0.0.Beta1. This security loophole allows for a potential null pointer dereference, enabling attackers to exploit the flaw remotely. Publicly available exploits could be leveraged in attacks, making it crucial for users to upgrade to version 1.0.0.Beta0 to mitigate the risks associated with this vulnerability.
Affected Version(s)
OpenARC 1.0.0.Beta1
OpenARC 1.0.0.Beta0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
