在 Cyrus SASL 中发现了一个基于堆的缓冲区溢出漏洞。DIGEST-MD5 插件中的 函数在应用 DIGEST-MD5 引号(即对特殊字符进行转义)之前,计算了用于挑战/响应字段所需的缓冲区大小,但在转义操作使值变长后,并未重新计算该大小。随后,这个尺寸不足的缓冲区被传递给 函数,导致基于堆的越界写入,其写入大小取决于攻击者可控的输入。恶意或中间人(on-path)的 DIGEST-MD5(或 HTTP Digest)服务器可以通过提供一个构造好的挑战字段(例如 realm 或 nonce),在连接的客户端
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Hardened Images | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
unknown |
any |
unknown |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106471 | 8.1 HIGH | Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult |
| CVE-2026-107176 | 6.8 MEDIUM | Cluster-samples-operator: role reads all secrets in openshift-config, not just pull-secret |
| CVE-2026-103868 | 6.5 MEDIUM | Pulp-container: registry credentials are reused across remotes in a worker |
| CVE-2026-103869 | 6.5 MEDIUM | Pulp-ansible: bearer tokens are reused across remotes in a worker |
| CVE-2026-107121 | 6.5 MEDIUM | Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg |
| CVE-2026-107174 | 6.4 MEDIUM | Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extr |
| CVE-2026-106067 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in hot color filter on oversized image |
| CVE-2026-106064 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions |
| CVE-2026-106065 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in pcx export on oversized image dimensions |
| CVE-2026-106066 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions |
| CVE-2026-107168 | 6.2 MEDIUM | M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars() |
| CVE-2026-107167 | 6.2 MEDIUM | M17n-lib: heap use-after-free write in re_init_ic() |
| CVE-2026-107169 | 6.2 MEDIUM | M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8 |
| CVE-2026-107151 | 5.9 MEDIUM | Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated request |
| CVE-2026-106061 | 5.5 MEDIUM | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file |
| CVE-2026-103870 | 5.0 MEDIUM | Pulp-rpm: distribution tree publish creates directories from .treeinfo ids |
| CVE-2026-107170 | 2.9 LOW | M17n-lib: null dereference in minput_open_im() after failed m17n_init() |
No comments yet