---
id: CVE-2026-107170
title: A flaw was found in m17n-lib
summary: >-
  A flaw was found in m17n-lib. A partial failure during library initialization
  can leave an internal driver pointer uninitialized. Under specific error
  conditions, such as system resource exhaustion or database corruption, an
  application …
severity: low
cvss: 2.9
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-476
vendor: Red Hat
product: m17n-lib
affected:
  - m17n-lib (all versions)
  - m17n-lib
  - m17n-lib (all versions)
  - m17n-lib (all versions)
  - m17n-lib (all versions)
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:18.000'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107170'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-107170'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2547411'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T17:40:52.159938Z'
ingestedAt: '2026-10-07T13:31:04.597Z'
---

## Overview

A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion or database corruption, an application attempting to open an input method dereferences this null pointer without proper validation. This issue causes the application to crash, resulting in a Denial of Service (DoS).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
