CVE-2026-68765

NameCVE-2026-68765
Descriptionhashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex characters for the ninth token field but decodes it into a fixed 256-byte buffer with no length check, allowing a maximal input to write up to 44 bytes past the buffer boundary into adjacent esalt fields and heap chunk metadata, potentially enabling heap corruption or memory access violations.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hashcat (PTS)bullseye6.1.1+ds1-1fixed
bookworm6.2.6+ds1-1fixed
trixie6.2.6+ds2-1fixed
forky, sid7.1.2+ds1-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hashcatsource(unstable)(not affected)

Notes

- hashcat <not-affected> (Vulnerable code not present)
Introduced with: https://github.com/hashcat/hashcat/commit/ef52453de9523f6a010652847b61cb340ed5daa5
Fixed by: https://github.com/hashcat/hashcat/commit/6f374c4ff7d5dc951530fbbbcf6b45e3c169b100

Search for package or bug name: Reporting problems