#1145171 hashcat: CVE-2026-68766 CVE-2026-68767 CVE-2026-68768

Package:
src:hashcat
Source:
src:hashcat
Submitter:
Salvatore Bonaccorso
Date:
2026-08-23 12:35:02 UTC
Severity:
normal
Tags:
#1145171#5
Date:
2026-08-23 12:32:39 UTC
From:
To:
Hi,

The following vulnerabilities were published for hashcat.

CVE-2026-68766[0]:
| hashcat fails to restrict command-line options when parsing restore
| files, allowing attackers to inject output-redirecting options like
| --outfile and --potfile-path. Attackers can craft restore files with
| malicious options to append attacker-controlled content to arbitrary
| files, enabling code execution when targeting shell startup files.


CVE-2026-68767[1]:
| hashcat's fgetl() function in src/filehandling.c writes a null
| terminator one byte past the caller's buffer when an input line is
| exactly the buffer length. Attackers can trigger this out-of-bounds
| heap write by providing a hash file, potfile, or wordlist containing
| a line of exactly HCBUFSIZ_LARGE bytes.


CVE-2026-68768[2]:
| hashcat contains a heap-based buffer overflow (out-of-bounds write)
| in the outfile_write() function in src/outfile.c. When assembling
| output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the
| function sequentially appends the username, separator, hash, and
| plaintext via memcpy without validating that the accumulated length
| stays within the buffer capacity. When run with --username --show
| against a crafted hash file containing an oversized username that
| nearly fills the buffer, the total assembled output exceeds the
| buffer, causing a heap buffer overflow that can corrupt memory and
| crash the process.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-68766
https://www.cve.org/CVERecord?id=CVE-2026-68766
[1] https://security-tracker.debian.org/tracker/CVE-2026-68767
https://www.cve.org/CVERecord?id=CVE-2026-68767
[2] https://security-tracker.debian.org/tracker/CVE-2026-68768
https://www.cve.org/CVERecord?id=CVE-2026-68768

Regards,
Salvatore