CVE-2026-41988Always-Incorrect Control Flow Implementation in Uuid

Severity
3.2LOWNVD
EPSS
0.0%
top 98.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23

Description

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:NExploitability: 1.4 | Impact: 1.4

Affected Packages163 packages

🔴Vulnerability Details

1
GHSA
GHSA-qmq6-f8pr-cx5x: uuid before 142026-04-23

📋Vendor Advisories

1
Red Hat
uuid: uuid: Unexpected data writes when using external output buffers with specific UUID versions2026-04-23

💬Community

1
Bugzilla
CVE-2026-41988 uuid: uuid: Unexpected data writes when using external output buffers with specific UUID versions2026-04-23