Bug 2547409 (CVE-2026-107168) - CVE-2026-107168 m17n-lib: Parser infinite loop on malformed UTF-8 in count_utf_8_chars()
Summary: CVE-2026-107168 m17n-lib: Parser infinite loop on malformed UTF-8 in count_ut...
Keywords:
Status: NEW
Alias: CVE-2026-107168
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2547603
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-07 12:01 UTC by OSIDB Bzimport
Modified: 2026-10-07 17:48 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-07 12:01:20 UTC
A flaw was found in m17n-lib. An invalid UTF-8 sequence containing a lead byte in the 0xFE-0xFF range can cause count_utf_8_chars() (src/mtext.c) to make no parsing progress, resulting in an infinite loop and sustained CPU consumption when processing crafted M-text input. Independently reproduced: a crafted .mim database entry containing byte 0xFF causes the plain build to spin at ~100% CPU until killed (confirmed via `time`: ~4.9s of CPU time consumed in a 5s window, process required external termination). Root cause confirmed in src/mtext.c: CHAR_UNITS_BY_HEAD_UTF8(0xFF) returns 0, so the scanning pointer in count_utf_8_chars() never advances. Upstream maintainer Kenichi Handa reviewed the report and confirmed the affected byte range is 0xFE-0xFF rather than the broader 0xFC-0xFF range originally suggested by the reporter.


Note You need to log in before you can comment on or make changes to this bug.