PT-2026-41439 · Gegl · Libbabl

Carter Yagemann

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2020-37239

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl free() twice on the same pointer without triggering detection, as libc's malloc metadata overwrites babl's signature field upon freeing, enabling potential memory corruption and code execution.

Exploit

Fix

Double Free

Weakness Enumeration

Related Identifiers

CVE-2020-37239

Affected Products

Libbabl