Impact
The vulnerability is caused by an error in popt’s poptConfigFileToString function which performs a short realloc that leads to heap metadata corruption. When an attacker supplies specially crafted configuration content that the host processes, it can corrupt heap memory and cause the affected process to crash, resulting in a denial of service condition.
Affected Systems
This flaw affects Red Hat products such as Red Hat Enterprise Linux releases 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4, as well as the popt library itself. No specific version information is provided, so all affected instantiations of popt on these platforms are potentially impacted.
Risk and Exploitability
The CVSS score of 2.5 indicates a low severity overall. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a limited risk of widespread exploitation. Exploitation would require the ability to supply or modify configuration data that is processed by popt, meaning attack may be local or require elevated privileges. As no public exploit is reported, the likelihood of an immediate threat is low, but the affected process becomes unavailable if the flaw is triggered.
OpenCVE Enrichment