PatchSiren cyber security CVE debrief
CVE-2026-48829 GNU CVE debrief
A NULL pointer dereference vulnerability exists in GNU SASL versions prior to 2.2.3, specifically within the DIGEST-MD5 authentication mechanism implementation. The flaw resides in lib/digest-md5/getsubopt.c and is triggered when parsing a known token that lacks an accompanying '=' character. This vulnerability affects both client and server implementations, allowing remote unauthenticated attackers to cause denial of service through application crashes. The issue was addressed in GNU SASL 2.2.3 via a code commit that properly handles malformed token input.
- Vendor
- GNU
- Product
- GNU SASL
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-24
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-24
- Advisory updated
- 2026-07-23
Who should care
Organizations running GNU SASL-based services with DIGEST-MD5 authentication enabled, particularly mail servers (SMTP, IMAP, POP3), XMPP servers, and other SASL-authenticated applications. System administrators maintaining Debian-based systems should prioritize updates per DSA-2026-00182. Developers integrating GNU SASL should review their authentication mechanism configurations and update dependencies.
Technical summary
The vulnerability exists in the DIGEST-MD5 mechanism's option parsing code within lib/digest-md5/getsubopt.c. When processing authentication tokens, the code fails to validate that a token includes a required '=' character before dereferencing pointers, resulting in a NULL pointer dereference. Both client and server code paths are affected. An attacker can trigger this by sending a crafted DIGEST-MD5 authentication exchange with a malformed token. The CVSS 3.1 score of 7.5 (HIGH) reflects the network accessibility, low attack complexity, and high availability impact with no confidentiality or integrity effects.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade GNU SASL to version 2.2.3 or later
- Apply distribution security updates for affected packages (Debian DSA-2026-00182)
- Review applications using GNU SASL for DIGEST-MD5 authentication and prioritize patching for internet-facing services
- Monitor GNU SASL help mailing list for additional guidance
Evidence notes
The vulnerability is confirmed through official GNU SASL project communications and a code commit on Codeberg. The fix commit (da9b5ae2962b014879e4a406c3b38f25aa70e97a) addresses the NULL pointer dereference in getsubopt.c. Debian has issued a security advisory (DSA-2026-00182) indicating coordinated disclosure and patch availability. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) confirms network attack vector with low complexity and high availability impact. CWE-476 (NULL Pointer Dereference) is the assigned weakness classification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48829 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48829
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48829 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48829
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://codeberg.org/gsasl/gsasl/commit/da9b5ae2962b014879e4a406c3b38f25aa70e97a
-
Source reference
Unverified legacy reference
URL: https://lists.debian.org/debian-security-announce/2026/msg00182.html
-
Source reference
Unverified legacy reference
URL: https://lists.gnu.org/archive/html/help-gsasl/2026-05/msg00000.html
-
Source reference
Unverified legacy reference
URL: https://lists.gnu.org/archive/html/help-gsasl/2026-05/msg00002.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.