A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-01 02:16
Updated : 2026-09-08 23:17
NVD link : CVE-2026-18743
Mitre link : CVE-2026-18743
CVE.ORG link : CVE-2026-18743
JSON object : View
Products Affected
No product.
CWE
CWE-131
Incorrect Calculation of Buffer Size
