CVE-2026-107161
Received Received - Intake

Heap-based Buffer Overflow in Cyrus SASL DIGEST-MD5 Plugin

Vulnerability report for CVE-2026-107161, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107161 is a heap-based buffer overflow in the Cyrus SASL library's DIGEST-MD5 plugin. The add_to_challenge() function miscalculates buffer size before applying DIGEST-MD5 quoting. When a malicious server sends crafted challenge fields with many escapable characters, the quoted value exceeds the buffer size, causing an out-of-bounds write during strcat(). This can crash client applications or potentially lead to arbitrary code execution.

Detection Guidance

Detecting this vulnerability requires monitoring for crashes in client applications using Cyrus SASL with DIGEST-MD5 or HTTP Digest authentication. Check logs for segmentation faults or heap corruption errors in applications like email clients or authentication services. Use tools like gdb to analyze crashes in saslauthd or applications linked to libsasl2.

Impact Analysis

If you use client applications relying on DIGEST-MD5 or HTTP Digest authentication, a malicious server could crash your application or execute arbitrary code. Exploitation requires you to authenticate against a malicious server, but the impact is severe due to potential code execution. The vulnerability is rated HIGH severity with CVSS 7.5.

Compliance Impact

This vulnerability could lead to unauthorized code execution or data breaches if exploited, potentially violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Organizations using affected Cyrus SASL versions must mitigate risks to maintain compliance.

Mitigation Strategies

Disable DIGEST-MD5 and HTTP Digest authentication in client applications. Remove the cyrus-sasl-md5 package if installed. Avoid authenticating against untrusted servers until a patch is available. Monitor vendor advisories for updates to the cyrus-sasl library.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107161. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart