CVE-2026-107169
Awaiting Analysis Awaiting Analysis - Queue

Null Pointer Dereference in m17n-lib Causes DoS

Vulnerability report for CVE-2026-107169, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A flaw was found in m17n-lib. An attacker could provide specially crafted or truncated UTF-8 input to trigger an unhandled null pointer dereference during text processing. This issue causes the application to crash unexpectedly, resulting in a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnu m17n-lib *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a null pointer dereference flaw in m17n-lib. It occurs when specially crafted or truncated UTF-8 input is processed, causing the application to crash unexpectedly. This leads to a Denial of Service (DoS) as the system becomes unavailable.

Detection Guidance

Detecting this vulnerability requires monitoring for crashes in applications using m17n-lib when processing UTF-8 input. Check application logs for segmentation faults or null pointer dereference errors during text processing. Use tools like gdb to analyze core dumps if crashes occur.

Impact Analysis

The vulnerability can cause your application to crash, making it unavailable for users. This disrupts normal operations and may lead to loss of service or data processing delays.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) by crashing applications processing UTF-8 text, which could disrupt services handling sensitive data. For GDPR, this may lead to disruptions in data processing systems, potentially violating availability requirements. For HIPAA, unexpected downtime could impact systems managing protected health information, affecting compliance with access and availability standards.

Mitigation Strategies

Since no official mitigation is available, consider disabling the affected component if possible. Monitor vendor updates for patches. If the component is non-critical, remove or restrict its use until a fix is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107169. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart