Description
A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion or database corruption, an application attempting to open an input method dereferences this null pointer without proper validation. This issue causes the application to crash, resulting in a Denial of Service (DoS).
Published: 2026-10-07
Score: 2.9 Low
EPSS: n/a
KEV: No
Impact: Denial of Service (application crash)
Action: Assess Impact
AI Analysis

Impact

A null dereference in the m17n-lib library occurs when an application attempts to open an input method after the library initialization partially fails. The incomplete initialization leaves an internal driver pointer uninitialized, and under conditions such as system resource exhaustion or database corruption the application dereferences this null pointer, causing an immediate crash. The weakness is a classic NULL pointer dereference (CWE‑476).

Affected Systems

The vulnerability affects Red Hat Enterprise Linux releases 10, 6, 7, 8, and 9. No specific patch versions are provided, so all installations of these versions are potentially impacted until a fix is released.

Risk and Exploitability

The CVSS score of 2.9 indicates low severity, and no EPSS score is available, implying that exploitation likelihood is not well understood or is low. The vulnerability is not listed in the CISA KEV catalog. Attack conditions require an application to invoke the problematic function on a system where resource exhaustion or database corruption has already occurred, making the attack vector essentially local. Because the flaw results only in a crash, the impact is limited to denial of service rather than compromise of confidentiality or integrity.

Generated by OpenCVE AI on October 7, 2026 at 14:55 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the latest Red Hat Enterprise Linux security updates, which may include a fix for this issue; if no patch is available, upgrade to a newer major release when it becomes available.
  • In environments where resource exhaustion or database corruption is a risk, avoid or disable application use of m17n-lib’s input method functions, or reconfigure those applications to disable input method support where feasible.
  • Continuously monitor application logs for crashes related to input method usage and alert administrators to potential denial‑of-service events.

Generated by OpenCVE AI on October 7, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion or database corruption, an application attempting to open an input method dereferences this null pointer without proper validation. This issue causes the application to crash, resulting in a Denial of Service (DoS).
Title M17n-lib: null dereference in minput_open_im() after failed m17n_init()
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-476
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T12:41:33.159Z

Reserved: 2026-10-07T11:29:09.081Z

Link: CVE-2026-107170

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T13:17:20.387

Modified: 2026-10-07T14:47:21.140

Link: CVE-2026-107170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T15:00:07Z

Weaknesses