Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107161— Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows malicious server to crash or compromise digest-md5 clients

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Cyrus SASL 中发现了一个基于堆的缓冲区溢出漏洞。DIGEST-MD5 插件中的 函数在应用 DIGEST-MD5 引号(即对特殊字符进行转义)之前,计算了用于挑战/响应字段所需的缓冲区大小,但在转义操作使值变长后,并未重新计算该大小。随后,这个尺寸不足的缓冲区被传递给 函数,导致基于堆的越界写入,其写入大小取决于攻击者可控的输入。恶意或中间人(on-path)的 DIGEST-MD5(或 HTTP Digest)服务器可以通过提供一个构造好的挑战字段(例如 realm 或 nonce),在连接的客户端

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 8

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107161

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows malicious server to crash or compromise digest-md5 clients
Source: CVE Program / CVE List V5
Vulnerability Description
A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-107161

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107161

请登录查看更多情报信息。

Other References for CVE-2026-107161 (2)

Same Patch Batch · Red Hat · 2026-10-07 · 18 CVEs total

CVE-2026-106471 8.1 HIGH Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult
CVE-2026-107176 6.8 MEDIUM Cluster-samples-operator: role reads all secrets in openshift-config, not just pull-secret
CVE-2026-103868 6.5 MEDIUM Pulp-container: registry credentials are reused across remotes in a worker
CVE-2026-103869 6.5 MEDIUM Pulp-ansible: bearer tokens are reused across remotes in a worker
CVE-2026-107121 6.5 MEDIUM Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg
CVE-2026-107174 6.4 MEDIUM Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extr
CVE-2026-106067 6.3 MEDIUM Gimp: gimp: heap buffer overflow in hot color filter on oversized image
CVE-2026-106064 6.3 MEDIUM Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions
CVE-2026-106065 6.3 MEDIUM Gimp: gimp: heap buffer overflow in pcx export on oversized image dimensions
CVE-2026-106066 6.3 MEDIUM Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions
CVE-2026-107168 6.2 MEDIUM M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()
CVE-2026-107167 6.2 MEDIUM M17n-lib: heap use-after-free write in re_init_ic()
CVE-2026-107169 6.2 MEDIUM M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8
CVE-2026-107151 5.9 MEDIUM Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated request
CVE-2026-106061 5.5 MEDIUM Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file
CVE-2026-103870 5.0 MEDIUM Pulp-rpm: distribution tree publish creates directories from .treeinfo ids
CVE-2026-107170 2.9 LOW M17n-lib: null dereference in minput_open_im() after failed m17n_init()

IV. Related Vulnerabilities

V. Comments for CVE-2026-107161

No comments yet


Leave a comment