Denial of Service Vulnerability in m17n-lib Affecting Red Hat Products
CVE-2026-107170
2.9LOW
What is CVE-2026-107170?
A flaw has been identified in the m17n-lib library where a partial failure during initialization may lead to an uninitialized internal driver pointer. This can occur in specific scenarios, such as when the system experiences resource exhaustion or if there is corruption in the database. When an application attempts to open an input method without proper validation of this pointer, it may dereference a null value, resulting in an application crash. This behavior can ultimately lead to a Denial of Service condition, affecting system availability.
References
CVSS V3.1
Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Shalitha Madhuwantha for reporting this issue.