Memory Corruption Vulnerability in Popt Affects Red Hat
CVE-2026-18743

2.5LOW

What is CVE-2026-18743?

A flaw exists in Popt that enables attackers to introduce specially crafted configuration content. When this content is loaded, it can trigger a memory corruption issue due to an error in the reallocation of buffers by the poptConfigFileToString function. Exploiting this vulnerability could lead to heap metadata corruption, which may render the affected process unavailable, resulting in denial of service.

Affected Version(s)

popt 1.11

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Matanya Moses (Checkpoint) for reporting this issue.
.