Description
A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the arc_parse_canon_t function of the OpenARC library's libopenarc/arc-canon.c component. An attacker can supply crafted input that triggers a null pointer dereference, causing the library to crash. The crash results in a denial of service condition. The weakness is reflected in CWE-476 and CWE-404 entries, indicating improper null handling.

Affected Systems

Trusted Domain Project OpenARC versions up to 1.0.0.Beta1 are affected. The flaw exists in the libopenarc/arc-canon.c module, which is part of the core OpenARC library used for canonicalizing ARC headers during inbound signature validation. Any deployment that loads this library and processes ARC data may be vulnerable.

Risk and Exploitability

The CVSS base score of 6.9 classifies the issue as moderate severity, and no EPSS data is available. The vulnerability is not listed in the CISA KEV catalog. Publicly released exploit code demonstrates that the flaw can be triggered remotely, giving an attacker a wide attack surface. Defenders should treat this as a non-negligible risk that could lead to service interruptions if left unpatched.

Generated by OpenCVE AI on September 28, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenARC to version 1.0.0.Beta0 to replace the vulnerable library.
  • Rebuild or reinstall any applications that link against OpenARC to ensure they use the updated binary.
  • Restart affected services or processes to load the upgraded library.

Generated by OpenCVE AI on September 28, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.
Title Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference
First Time appeared Trusted Domain Project
Trusted Domain Project openarc
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:trusted_domain_project:openarc:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project openarc
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Openarc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T01:15:11.424Z

Reserved: 2026-09-27T08:22:09.540Z

Link: CVE-2026-100895

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T02:17:19.437

Modified: 2026-09-28T02:17:19.437

Link: CVE-2026-100895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T03:30:07Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference