Impact
A null dereference in the m17n-lib library occurs when an application attempts to open an input method after the library initialization partially fails. The incomplete initialization leaves an internal driver pointer uninitialized, and under conditions such as system resource exhaustion or database corruption the application dereferences this null pointer, causing an immediate crash. The weakness is a classic NULL pointer dereference (CWE‑476).
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 10, 6, 7, 8, and 9. No specific patch versions are provided, so all installations of these versions are potentially impacted until a fix is released.
Risk and Exploitability
The CVSS score of 2.9 indicates low severity, and no EPSS score is available, implying that exploitation likelihood is not well understood or is low. The vulnerability is not listed in the CISA KEV catalog. Attack conditions require an application to invoke the problematic function on a system where resource exhaustion or database corruption has already occurred, making the attack vector essentially local. Because the flaw results only in a crash, the impact is limited to denial of service rather than compromise of confidentiality or integrity.
OpenCVE Enrichment