PatchSiren cyber security CVE debrief
CVE-2026-107161 Red Hat CVE debrief
A heap-based buffer overflow flaw was found in Cyrus SASL, specifically in the DIGEST-MD5 plugin. The add_to_challenge() function computes the buffer size needed for a challenge/response field before applying DIGEST-MD5 quoting, but fails to recompute the size when quoting makes the value longer. This results in a heap-based out-of-bounds write when the buffer is passed to strcat(). A malicious or on-path DIGEST-MD5 server can trigger this flaw by supplying a crafted challenge field, likely causing the client application to crash.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Red Hat Enterprise Linux and OpenShift Container Platform systems, especially those exposed to untrusted or on-path servers, should assess their exposure and prioritize verification and updates of cyrus-sasl packages.
Why it matters
Defenders should prioritize verifying and updating cyrus-sasl packages on affected Red Hat Enterprise Linux and OpenShift Container Platform systems, especially those exposed to untrusted or on-path servers, to prevent potential crashes or compromise.
- Potential client application crashes or compromise due to heap-based buffer overflow
- Need for verification and updates of cyrus-sasl packages on affected systems
- Possible exposure to untrusted or on-path servers
- Required monitoring for and response to potential attacks targeting this vulnerability
Technical summary
The add_to_challenge() function in the DIGEST-MD5 plugin of Cyrus SASL is vulnerable to a heap-based buffer overflow. A malicious server can supply a crafted challenge field to trigger this flaw, potentially causing the client application to crash or be compromised. This vulnerability is particularly concerning for defenders responsible for Red Hat Enterprise Linux and OpenShift Container Platform systems, especially those exposed to untrusted or on-path servers. The flaw results from the function's computation of the buffer size needed for a challenge/response field before applying DIGEST-MD5 quoting, but failing to recompute the size when quoting makes the value longer.
Defensive priority
Defenders should prioritize verifying and updating cyrus-sasl packages on affected systems, especially those exposed to untrusted or on-path servers.
Recommended defensive actions
- Verify and update cyrus-sasl packages on affected Red Hat Enterprise Linux and OpenShift Container Platform systems
- Review and restrict exposure of affected systems to untrusted or on-path servers
- Monitor for and respond to potential attacks targeting this vulnerability
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. Red Hat has also provided a reference to their security advisory for CVE-2026-107161. Defenders should verify and review these sources for accurate information. The vulnerability details indicate a heap-based buffer overflow flaw in Cyrus SASL, specifically in the DIGEST-MD5 plugin. Evidence from these sources suggests that a malicious server can trigger this flaw by supplying a crafted challenge field, potentially causing the to
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107161 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107161
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107161 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107161
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows malicious server to cra
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107161.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-107161
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.