CVE-2026-100895: Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference
A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arcparsecanont in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trusted Domain Project OpenARC libopenarcto a version that resolves this vulnerability.Fixed in 1.0.0.Beta0
Event History
Frequently Asked Questions
What is the practical impact of successful exploitation?
Successful exploitation causes a null pointer dereference in libopenarc, resulting in an availability impact. The provided severity vector indicates no confidentiality or integrity impact.
Does an attacker need credentials or user interaction?
No. The severity vector indicates the issue is remotely reachable, has low attack complexity, requires no privileges, and requires no user interaction.
Are publicly available exploits a concern for this issue?
Yes. The exploit has been released publicly and may be used in attacks, which increases the likelihood of exploitation.
Which versions should be remediated?
OpenARC versions up to 1.0.0.Beta1 are identified as affected. The provided remediation guidance recommends upgrading to version 1.0.0.Beta0.