Answer in brief
CVE-2026-107167 records a Medium severity (CVSS 6.2) vulnerability in M17n-lib: heap use-after-free write in re_init_ic(). The current sources do not mark it as known exploited. The current feed maps Red Hat/m17n-lib (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Red Hat/m17n-lib (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Red Hat/m17n-libgeneric | * | Not reported |
Published upstream
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 7, 2026
A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context object but subsequently attempts to write to that freed memory. This issue can cause applications relying on the library to crash, leading to a Denial of Service (DoS), or potentially allow arbitrary code execution.
Quoted source text, attributed separately from HOL analysis.