Impact
A crafted input containing an invalid UTF‑8 sequence triggers an infinite loop in the m17n‑lib function used for counting UTF‑8 characters. The loop causes the application to consume sustained high CPU resources, eventually denying service to legitimate users.
Affected Systems
The flaw affects Red Hat Enterprise Linux releases 10 through 9, as the m17n‑lib library is bundled with these operating systems. No specific patched version was listed, so systems running any of the affected RHEL versions should be considered vulnerable.
Risk and Exploitability
Based on the description, the likely attack vector is delivering crafted UTF‑8 data to an application that uses m17n‑lib, which triggers the infinite loop. The CVSS score of 6.2 indicates a moderate severity. Because the EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, historical exploitation probability is unclear; however, the infinite loop can still be triggered with crafted input, indicating a potential remote attack vector through untrusted data processed by applications that depend on m17n‑lib. The impact is limited to denial of service rather than data breach or privilege escalation.
OpenCVE Enrichment