CVE-2026-48829: Null Pointer Dereference
Published May 24, 2026
·Updated
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
Affected Software
2 affected componentsFixes available
GNU GNU SASL<2.2.3
debian/gsasl<=1.10.0-4+deb11u1, <=2.2.0-1, <=2.2.2-1.1
2.2.0-1+deb12u12.2.2-1.1+deb13u12.2.3-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gsaslto a version that resolves this vulnerability.Fixed in 2.2.0-1+deb12u1Fixed in 2.2.2-1.1+deb13u1Fixed in 2.2.3-1 - Upgrade
Upgrade
GNU SASL (DIGEST-MD5 / lib/digest-md5/getsubopt.c)to a version that resolves this vulnerability.Fixed in 2.2.3
Event History
May 24, 2026
CVE Published
via MITRE·02:22 AM
Data Sourced
via MITRE·02:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Jun 1, 2026
Data Sourced
via Ubuntu·06:32 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:33 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-48829?
CVE-2026-48829 has a high severity rating of 7.5.
2
How do I fix CVE-2026-48829?
To fix CVE-2026-48829, update GNU SASL to version 2.2.3 or later.
3
What type of vulnerability is CVE-2026-48829?
CVE-2026-48829 is a null pointer dereference vulnerability.
4
Which software is affected by CVE-2026-48829?
CVE-2026-48829 affects GNU SASL before version 2.2.3.
5
What impact does CVE-2026-48829 have on systems?
CVE-2026-48829 can lead to a denial of service due to a NULL pointer dereference.