Heap-Based Buffer Overflow in Cyrus SASL DIGEST-MD5 Plugin
CVE-2026-107161

7.5HIGH

What is CVE-2026-107161?

A heap-based buffer overflow vulnerability exists in the DIGEST-MD5 plugin of Cyrus SASL. The issue arises when the add_to_challenge() function computes the required buffer size for a challenge/response field without accounting for lengthening due to quoting special characters. This flawed calculation leads to an under-sized buffer being utilized in the strcat() function, resulting in a potential out-of-bounds write. An attacker can exploit this flaw by crafting a malicious challenge field, such as realm or nonce, from an on-path DIGEST-MD5 server. This exploitation can cause the client application to crash, posing significant risks to application stability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Bruno Fournier and Found by AISLE in partnership with Red Hat.
.