PatchSiren cyber security CVE debrief
CVE-2026-107170 Red Hat CVE debrief
A flaw in m17n-lib causes a null pointer dereference in minput_open_im() after a failed m17n_init(). This issue results in a Denial of Service (DoS) when an application attempts to open an input method under specific error conditions. The vulnerability is triggered by a partial failure during library initialization, which leaves an internal driver pointer uninitialized. This can happen due to system resource exhaustion or database corruption. As a result, defenders and administrators of systems using m17n-lib for input methods should be aware of this issue and consider patching or mitigating it to prevent potential DoS attacks.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- LOW 2.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders and administrators of systems using m17n-lib for input methods should assess their exposure and consider patching or mitigating this vulnerability. This includes verifying if applications using m17n-lib are vulnerable and reviewing the official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Why it matters
This vulnerability in m17n-lib can cause a Denial of Service (DoS) and defenders should assess their exposure, especially in systems using m17n-lib for input methods.
- Potential Denial of Service (DoS) attacks
- Need to verify if applications using m17n-lib are vulnerable
- Requires patching or mitigation to prevent exploitation
- Limited information on specific version vulnerabilities
Technical summary
The m17n-lib library has a flaw that can cause a null pointer dereference in the minput_open_im() function after a failed m17n_init(). This can lead to a Denial of Service (DoS) when an application attempts to open an input method under specific error conditions. The vulnerability is triggered by a partial failure during library initialization, which leaves an internal driver pointer uninitialized. This can happen due to system resource exhaustion or database corruption. The CVE record and source item provide details on the vulnerability, including its cause and potential impact.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially in systems using m17n-lib for input methods.
Recommended defensive actions
- Assess exposure of m17n-lib in your environment
- Verify if applications using m17n-lib are vulnerable
- Consider patching or mitigating the vulnerability
- Monitor for potential DoS attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including its cause and potential impact. However, specific version information and remediation steps are not provided. Defenders should verify if applications using m17n-lib are vulnerable and assess their exposure. The vulnerability has a CVSS score of 2.9 and is considered LOW severity. It is essential to review the official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107170 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107170
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107170 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107170
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
M17n-lib: null dereference in minput_open_im() after failed m17n_init()
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107170.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-107170
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.