Back

CRITICAL

ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.

Published Mar 19, 2026

Description

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

Affected products

Remediation

Red Hat statement

This Moderate impact vulnerability in ncurses affects Red Hat Enterprise Linux 10.0.z and 10.1.z. A buffer overflow in the `analyze_string()` function, exploitable through the `infocmp` utility, could lead to arbitrary code execution. Red Hat Enterprise Linux 6-ELS, 7-ELS, 8.x, 9.x, and OpenShift Container Platform are not affected as the vulnerable code is not present in these versions. Exploitation of this vulnerability requires that an affected application processes malicious data; this requires either user interaction or privileges on an affected system.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 19, 2026
Updated Jun 2, 2026
Reserved Jan 9, 2026
CISA Vulnrichment
Updated Mar 24, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 19, 2026