Home

Description

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

PUBLISHED Reserved 2026-05-24 | Published 2026-05-24 | Updated 2026-05-24 | Assigner mitre




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-476 NULL Pointer Dereference

Product status

Default status
unaffected

Any version before 2.2.3
affected

References

lists.gnu.org/archive/html/help-gsasl/2026-05/msg00002.html

codeberg.org/...mit/da9b5ae2962b014879e4a406c3b38f25aa70e97a

lists.debian.org/debian-security-announce/2026/msg00182.html

lists.gnu.org/archive/html/help-gsasl/2026-05/msg00000.html

cve.org (CVE-2026-48829)

nvd.nist.gov (CVE-2026-48829)

Download JSON