DEBIAN-CVE-2026-2644

Source
https://security-tracker.debian.org/tracker/CVE-2026-2644
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2644.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-2644
Upstream
Published
2026-02-18T07:16:11.230Z
Modified
2026-02-21T10:01:44.232853Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation of the argument variable index with the input 2147483648 causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

References

Affected packages

Debian:11 / minisat2

Package

Name
minisat2
Purl
pkg:deb/debian/minisat2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*
1:2.2.1-5
1:2.2.1-6
1:2.2.1-7
1:2.2.1-8

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2644.json"

Debian:12 / minisat2

Package

Name
minisat2
Purl
pkg:deb/debian/minisat2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*
1:2.2.1-5
1:2.2.1-6
1:2.2.1-7
1:2.2.1-8

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2644.json"

Debian:13 / minisat2

Package

Name
minisat2
Purl
pkg:deb/debian/minisat2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*
1:2.2.1-8

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2644.json"

Debian:14 / minisat2

Package

Name
minisat2
Purl
pkg:deb/debian/minisat2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*
1:2.2.1-8

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2644.json"