← Advisories

Empty comment causes a null dereference in libConfuse

fixed

Details

Product libConfuse
Vendor libconfuse
Affected v3.3 through commit 8bc87dc48053; fixed in df808867a8cc
CWE CWE-476
Severity low
Status fixed

Timeline

Found 18 Jul 2026
Reported 20 Jul 2026
Fixed 20 Jul 2026
Disclosed 21 Jul 2026

References

Notes

When comment retention is enabled with CFGF_COMMENTS, the one-byte input # causes the lexer to emit a comment token with a null value. The parser passes that value to strdup(), terminating the process with a null-pointer dereference while parsing attacker-controlled configuration text.

All 31 AFL crash files collected from the schema and key-value harnesses deduplicate to the same fault. The minimal PoC reproduces on v3.3 and current master 8bc87dc48053. A proposed lexer fix was verified against current master: the PoC then returns successfully with no ASan/UBSan finding.

The issue was reported publicly as libconfuse/libconfuse#187, following the project’s documented issue-tracker route. Maintainer Joachim Wiberg confirmed the report, applied the fix in df808867a8cc, and added regression tests for empty #, //, and block comments. The commit credits glitchfox as author and Signed-off-by and is scheduled to ship in libConfuse 3.4.

I rebuilt that exact upstream commit and replayed the original PoC under ASan/UBSan. Parsing returned successfully with no sanitizer finding.