Description
A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an infinite loop. This issue leads to sustained high CPU utilization, resulting in a Denial of Service (DoS) for the affected application.
Published: 2026-10-07
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via CPU exhaustion
Action: Patch
AI Analysis

Impact

A crafted input containing an invalid UTF‑8 sequence triggers an infinite loop in the m17n‑lib function used for counting UTF‑8 characters. The loop causes the application to consume sustained high CPU resources, eventually denying service to legitimate users.

Affected Systems

The flaw affects Red Hat Enterprise Linux releases 10 through 9, as the m17n‑lib library is bundled with these operating systems. No specific patched version was listed, so systems running any of the affected RHEL versions should be considered vulnerable.

Risk and Exploitability

Based on the description, the likely attack vector is delivering crafted UTF‑8 data to an application that uses m17n‑lib, which triggers the infinite loop. The CVSS score of 6.2 indicates a moderate severity. Because the EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, historical exploitation probability is unclear; however, the infinite loop can still be triggered with crafted input, indicating a potential remote attack vector through untrusted data processed by applications that depend on m17n‑lib. The impact is limited to denial of service rather than data breach or privilege escalation.

Generated by OpenCVE AI on October 7, 2026 at 16:21 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the latest Red Hat Enterprise Linux update that includes the fixed m.
  • Restrict or sanitize UTF‑8 input for applications using m17n‑lib to prevent malformed sequences from reaching the parser.
  • Implement system resource limits or CPU usage ceilings (e.g., cgroups, rate limiting) for affected services to mitigate denial‑of‑service impact while a patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an infinite loop. This issue leads to sustained high CPU utilization, resulting in a Denial of Service (DoS) for the affected application.
Title M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-835
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T14:41:18.595Z

Reserved: 2026-10-07T11:29:09.081Z

Link: CVE-2026-107168

cve-icon Vulnrichment

Updated: 2026-10-07T14:41:15.403Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T13:17:20.183

Modified: 2026-10-07T15:17:18.870

Link: CVE-2026-107168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:30:17Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')