CVE-2019-19905: Nethack

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.

Affected products

  • Nethack Nethack: from 3.6.0, before 3.6.4 (fixed in 3.6.4)

Published 2019-12-19. Last modified 2026-06-17.