CVE-2026-107170
Awaiting Analysis Awaiting Analysis - Queue

m17n-lib Uninitialized Pointer Dereference DoS

Vulnerability report for CVE-2026-107170, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion or database corruption, an application attempting to open an input method dereferences this null pointer without proper validation. This issue causes the application to crash, resulting in a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference flaw in the m17n-lib library. During initialization, if a partial failure occurs, an internal driver pointer remains uninitialized. When an application tries to open an input method under specific error conditions like system resource exhaustion or database corruption, it crashes due to dereferencing this null pointer, causing a Denial of Service (DoS).

Detection Guidance

Detecting this vulnerability requires checking for crashes in applications using m17n-lib during initialization failures. Monitor logs for segmentation faults or application crashes when system resources are low or databases are corrupted. No specific commands are provided in the resources.

Impact Analysis

The vulnerability can cause applications using m17n-lib to crash, leading to a Denial of Service (DoS). This disrupts normal operations and may require restarting the affected application or system. In rare cases with privileged access, it could potentially allow unauthorized code execution.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) by crashing applications due to a NULL pointer dereference. It does not directly affect data confidentiality or integrity but may impact system availability. Compliance with standards like GDPR or HIPAA typically requires maintaining system availability and protecting data integrity. A DoS could disrupt services, potentially affecting compliance if critical systems become unavailable.

Mitigation Strategies

No official mitigation is available from Red Hat. Users should monitor for updates or vendor-specific patches. Avoid running applications under resource exhaustion or corrupted database conditions to reduce risk. Consider disabling affected input methods if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107170. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart