In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-24 04:16
Updated : 2026-07-23 17:10
NVD link : CVE-2026-48829
Mitre link : CVE-2026-48829
CVE.ORG link : CVE-2026-48829
JSON object : View
Products Affected
No product.
CWE
CWE-476
NULL Pointer Dereference
