Source: popt
Version: 1.19+dfsg-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for popt.

CVE-2026-18739[0]:
| A flaw was found in popt, a command-line option parsing library. An
| off-by-one error in the poptStuffArgs function, when repeatedly
| called by a host application or through deep alias nesting, can lead
| to corruption of internal program data. This corruption could
| potentially enable a local attacker to execute arbitrary code if the
| host application then unsafely processes the altered data.


CVE-2026-18839[1]:
| An integer underflow was found in the popt library when formatting
| help text for option tables that exceed the terminal width. A local
| user who can cause an application to print help under those
| conditions may cause that application to crash or fail to display
| help, resulting in a denial of service of the affected application.

AFAICS the only references right now are to the Red Hat bugzilla.

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18739
    https://www.cve.org/CVERecord?id=CVE-2026-18739
[1] https://security-tracker.debian.org/tracker/CVE-2026-18839
    https://www.cve.org/CVERecord?id=CVE-2026-18839

Regards,
Salvatore

Reply via email to