Record summary

CVE-2026-18739 has a selected CVSS score of 2.5 (low).

Description

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List

Affected products and versions

8
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10popt

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 6

Browse Red Hat / Red Hat Enterprise Linux 6popt

Default status: unknown

CVE ListVersion data not supplied

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7popt

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8popt

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 9

Browse Red Hat / Red Hat Enterprise Linux 9popt

Default status: affected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imagespopt

Default status: affected

CVE ListVersion data not supplied

Red Hat OpenShift Container Platform 4

Browse Red Hat / Red Hat OpenShift Container Platform 4rhcos

Default status: unknown

CVE ListVersion data not supplied

Default status: unaffected

CVE List1.1.1 to < *affected

References

3