CVE-2019-11638: GNU Recutils

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.

Affected products

  • GNU Recutils: version 1.8 only

Published 2019-05-01. Last modified 2026-06-17.