CVE Vulnerabilities

CVE-2026-48829

NULL Pointer Dereference

Published: May 24, 2026 | Modified: Jun 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
GsaslUbuntudevel*
GsaslUbuntunoble*
GsaslUbuntuquesting*
GsaslUbunturesolute*
GsaslUbuntuupstream*

Potential Mitigations

References