access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2026-18839 CVE-2026-18839
LOW
Popt-devel: popt-static: size_t underflow in singleoptionhelp
Record summary
CVE-2026-18839 has a selected CVSS score of 2.2 (low).
Description
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
8| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | 1.13 to < * | affected |
References
3RHBZ#2511010issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2511010 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-18839