THREAT OPS › Threat News › [NVD] CVE-2026-68767 (MEDIUM 6.1) — hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exa
[NVD] CVE-2026-68767 (MEDIUM 6.1) — hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exa
CVE-2026-68767 CVSS: 6.1 MEDIUM Published: 2026-08-22T15:16:20.770
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.
Indicators of compromise
- CVE-2026-68767cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68767