THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-68767 (MEDIUM 6.1) — hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exa

[NVD] CVE-2026-68767 (MEDIUM 6.1) — hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exa

mednvdPublished 2026-08-22

CVE-2026-68767 CVSS: 6.1 MEDIUM Published: 2026-08-22T15:16:20.770

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68767