Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108063— Libhangul: null pointer dereference in hanja_new() when looking up a malformed hanja dictionary entry

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 libhangul 中发现了一个缺陷。该库在解析汉字词典文件时,未能验证条目在其键值对中包含有效的值。攻击者通过向查询该词典的应用程序提供一个特制的词典文件,即可触发应用程序出现非预期崩溃,从而导致拒绝服务(DoS)攻击。

CVSS 5.5 · Medium

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 5

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108063

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Libhangul: null pointer dereference in hanja_new() when looking up a malformed hanja dictionary entry
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in libhangul. When parsing Hanja dictionary files, the library fails to verify that an entry contains a valid value alongside its key. By providing a specially crafted dictionary file to an application that queries it, an attacker can trigger an unexpected application crash, resulting in a Denial of Service (DoS).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-108063

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108063

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-108063 (1)

News Coverage for CVE-2026-108063 (1)

Same Patch Batch · Red Hat · 2026-10-09 · 6 CVEs total

CVE-2026-107935 9.3 CRITICAL Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via
CVE-2026-108119 6.3 MEDIUM Busybox: busybox: tar extraction-root escape via deferred symlink/hardlink creation bypass
CVE-2026-108093 5.5 MEDIUM Gimp: gimp: denial of service via null pointer dereference in xcf simulation parasite load
CVE-2026-107889 5.5 MEDIUM Keycloak-services: keycloak-services: stored xss on login page via kcsanitize bypass
CVE-2026-107655 4.0 MEDIUM Cups: null pointer dereference via embedded job ticket comments allows remote denial of se

IV. Related Vulnerabilities

V. Comments for CVE-2026-108063

No comments yet


Leave a comment