CVE-2026-48829

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-24 04:16

Updated : 2026-07-23 17:10


NVD link : CVE-2026-48829

Mitre link : CVE-2026-48829

CVE.ORG link : CVE-2026-48829


JSON object : View

Products Affected

No product.

CWE
CWE-476

NULL Pointer Dereference