#1146722 popt: CVE-2026-18739 CVE-2026-18839

Package:
src:popt
Source:
src:popt
Submitter:
Salvatore Bonaccorso
Date:
2026-09-04 19:01:02 UTC
Severity:
normal
Tags:
#1146722#5
Date:
2026-09-04 19:00:24 UTC
From:
To:
Hi,

The following vulnerabilities were published for popt.

CVE-2026-18739[0]:
| A flaw was found in popt, a command-line option parsing library. An
| off-by-one error in the poptStuffArgs function, when repeatedly
| called by a host application or through deep alias nesting, can lead
| to corruption of internal program data. This corruption could
| potentially enable a local attacker to execute arbitrary code if the
| host application then unsafely processes the altered data.


CVE-2026-18839[1]:
| An integer underflow was found in the popt library when formatting
| help text for option tables that exceed the terminal width. A local
| user who can cause an application to print help under those
| conditions may cause that application to crash or fail to display
| help, resulting in a denial of service of the affected application.

AFAICS the only references right now are to the Red Hat bugzilla.

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18739
https://www.cve.org/CVERecord?id=CVE-2026-18739
[1] https://security-tracker.debian.org/tracker/CVE-2026-18839
https://www.cve.org/CVERecord?id=CVE-2026-18839

Regards,
Salvatore