git: c17f7b589d25 - main - security/vuxml: Add entries for popt CVE-2026-18743 and CVE-2026-18739
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 23 Sep 2026 04:30:56 UTC
The branch main has been updated by diizzy:
URL: https://cgit.FreeBSD.org/ports/commit/?id=c17f7b589d25f69af081412d388bedcdc249b215
commit c17f7b589d25f69af081412d388bedcdc249b215
Author: Daniel Engberg <diizzy@FreeBSD.org>
AuthorDate: 2026-09-23 04:29:43 +0000
Commit: Daniel Engberg <diizzy@FreeBSD.org>
CommitDate: 2026-09-23 04:29:46 +0000
security/vuxml: Add entries for popt CVE-2026-18743 and CVE-2026-18739
PR: 298326
---
security/vuxml/vuln/2026.xml | 63 ++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 63 insertions(+)
diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 364289bcc3b0..5c0f13735753 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,66 @@
+ <vuln vid="0142953c-b716-11f1-a70f-00a0980083d7">
+ <topic>popt -- Out-of-bounds Write</topic>
+ <affects>
+ <package>
+ <name>popt</name>
+ <range><le>1.19_2,1</le></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>https://access.redhat.com/errata/RHSA-2026:56984 reports:</p>
+ <blockquote cite="https://access.redhat.com/errata/RHSA-2026:56984">
+ <p>A flaw was found in popt, a command-line option parsing library.
+ An off-by-one error in the poptStuffArgs function, when repeatedly
+ called by a host application or through deep alias nesting, can
+ lead to corruption of internal program data. This corruption could
+ potentially enable a local attacker to execute arbitrary code if
+ the host application then unsafely processes the altered data.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2026-18739</cvename>
+ <url>https://cveawg.mitre.org/api/cve/CVE-2026-18739</url>
+ </references>
+ <dates>
+ <discovery>2026-08-04</discovery>
+ <entry>2026-09-23</entry>
+ </dates>
+ </vuln>
+
+ <vuln vid="e86be66a-b715-11f1-a70f-00a0980083d7">
+ <topic>popt -- Incorrect Calculation of Buffer Size</topic>
+ <affects>
+ <package>
+ <name>popt</name>
+ <range><le>1.19_2,1</le></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>https://access.redhat.com/errata/RHSA-2026:56984 reports:</p>
+ <blockquote cite="https://access.redhat.com/errata/RHSA-2026:56984">
+ <p>A flaw was found in popt. This vulnerability allows an attacker
+ to provide specially crafted configuration content to a host, which,
+ when loaded, can lead to a small memory corruption issue. This
+ occurs because of an error in how the `poptConfigFileToString`
+ function reallocates memory for buffers. Successful exploitation
+ could result in heap metadata corruption, potentially causing the
+ affected process to become unavailable (denial of service).</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2026-18743</cvename>
+ <url>https://cveawg.mitre.org/api/cve/CVE-2026-18743</url>
+ </references>
+ <dates>
+ <discovery>2026-09-01</discovery>
+ <entry>2026-09-23</entry>
+ </dates>
+ </vuln>
+
<vuln vid="6690917c-b657-11f1-ad2b-40b034429ecf">
<topic>p5-Dancer2 -- Multiple vulnerabilities</topic>
<affects>