CVE detail
CVE-2020-37239 — CVE-2020-37239
Published 2026-05-16 · Modified 2026-06-17 · Source nvd
CRITICAL
severity
CVSS-derived band
0.0046
EPSS probability
exploitation probability, 30d
38.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwrites babl's signature field upon freeing, enabling potential memory corruption and code execution.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References