High severity7.5NVD Advisory· Published May 24, 2026· Updated Jul 23, 2026
CVE-2026-48829
CVE-2026-48829
Description
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/gsasl&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/gsasl&distro=openSUSE%20Tumbleweed
< 2.2.1-160000.3.1+ 1 more
- (no CPE)range: < 2.2.1-160000.3.1
- (no CPE)range: < 2.2.3-1.1
Patches
Vulnerability mechanics
References
5- codeberg.org/gsasl/gsasl/commit/da9b5ae2962b014879e4a406c3b38f25aa70e97anvd
- lists.debian.org/debian-lts-announce/2026/06/msg00007.htmlnvd
- lists.debian.org/debian-security-announce/2026/msg00182.htmlnvd
- lists.gnu.org/archive/html/help-gsasl/2026-05/msg00000.htmlnvd
- lists.gnu.org/archive/html/help-gsasl/2026-05/msg00002.htmlnvd
News mentions
0No linked articles in our index yet.