CVE-2026-18839 PUBLISHED

Popt-devel: popt-static: size_t underflow in singleoptionhelp

Assigner: redhat
Reserved: 04.08.2026 Published: 05.08.2026 Updated: 06.08.2026

An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L
CVSS Score: 2.2

Product Status

Vendor rpm-software-management
Product popt
Versions Default: unaffected
  • affected from 1.13 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 6
Versions Default: unknown
Vendor Red Hat
Product Red Hat Enterprise Linux 7
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected
Vendor Red Hat
Product Red Hat Hardened Images
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected

Credits

  • Red Hat would like to thank Matanya Moses (Checkpoint) for reporting this issue.

References

Problem Types

  • Integer Underflow (Wrap or Wraparound) CWE