Executive brief
popt is a widely-used C library for parsing command-line arguments in applications. An off-by-one error in the poptStuffArgs function can corrupt internal program data when the function is called repeatedly, potentially allowing a local attacker to execute arbitrary code if the host application unsafely processes the corrupted data.
Technical details
The vulnerability is an off-by-one error in the poptStuffArgs function in popt's command-line option parsing library. The flaw is triggered when poptStuffArgs is repeatedly called (either by a host application directly or through deep alias nesting), causing corruption of internal program data structures. An attacker with local access could exploit this to corrupt data in memory; if the host application then processes this corrupted data unsafely, arbitrary code execution may be possible. The attack vector is local, and exploitation depends on the specific usage patterns and vulnerability of downstream applications that use popt.
Affected products
- popt Project popt
Timeline
- 2026-08-04: disclosed