CVE Vulnerabilities

CVE-2025-65411

NULL Pointer Dereference

Published: Dec 30, 2025 | Modified: Jan 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
UnrtfUnrtf_project0.21.10 (including)0.21.10 (including)
UnrtfUbuntuplucky*

Potential Mitigations

References