{"id":"CVE-2026-18839","title":"An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width","summary":"An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to c…","severity":"low","cvss":2.2,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L","cwe":["CWE-191"],"vendor":"rpm-software-management","product":"popt","affected":["popt >= 1.13 < *","popt-main (all versions)","popt (all versions)","popt","popt (all versions)","popt (all versions)","popt (all versions)","openshift/ose-rhel-coreos-8 (all versions)","openshift/ose-rhel-coreos-9 (all versions)"],"published":"2026-08-05","updated":"2026-10-08","sourceUpdated":"2026-10-08T15:17:52.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18839","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:77932","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18839","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511010","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-06T13:33:56.244752Z"},"epss":0.00114,"epssPercentile":0.0135,"ingestedAt":"2026-10-08T15:49:37.974Z","slug":"CVE-2026-18839","body":"## Overview\n\nAn integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":12,"depthScoreParts":{"impact":12.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}