CVE-2026-48850

Name
CVE-2026-48850
Description
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://lists.tartarus.org/pipermail/putty-announce/2026/000042.html
cve@mitre.org https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/rsakex-double-free.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:* putty >= 0.72 < 0.84

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
putty edge-main 0.81-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty edge-main 0.80-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty edge-main 0.76-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty edge-main 0.74-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty edge-main 0.73-r0 None possibly vulnerable
putty edge-community 0.83-r2 None possibly vulnerable
putty edge-community 0.83-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
putty edge-community 0.83-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
putty edge-community 0.82-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
putty edge-community 0.81-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty edge-community 0.80-r0 None possibly vulnerable
putty edge-community 0.76-r0 None possibly vulnerable
putty edge-community 0.74-r0 None possibly vulnerable
putty edge-community 0.73-r0 None possibly vulnerable
putty 3.23-community 0.83-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
putty 3.19-main 0.81-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty 3.19-main 0.80-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty 3.19-main 0.76-r0 None possibly vulnerable
putty 3.19-main 0.74-r0 None possibly vulnerable
putty 3.19-main 0.73-r0 None possibly vulnerable