quickjs-ng quickjs quickjs.c js_typed_array_sort heap-based overflow
Published Jan 10, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.46%
Description
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 53eefbcd695165a3bd8c584813b472cb4a69fbf5. To fix this issue, it is recommended to deploy a patch.
Affected products
-
- Version 0.1StatusaffectedConstraints-
- Version 0.10StatusaffectedConstraints-
- Version 0.11.0StatusaffectedConstraints-
- Version 0.2StatusaffectedConstraints-
- Version 0.3StatusaffectedConstraints-
- Version 0.4StatusaffectedConstraints-
- Version 0.5StatusaffectedConstraints-
- Version 0.6StatusaffectedConstraints-
- Version 0.7StatusaffectedConstraints-
- Version 0.8StatusaffectedConstraints-
- Version 0.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Quickjs-NG | Quickjs | n/a |
|
- ≤ 0.11.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated Moderate for Red Hat. A heap-based buffer overflow in the `js_typed_array_sort` function of `quickjs.c` in `quickjs-ng` can be exploited remotely with user interaction. This flaw could lead to information disclosure, denial of service, or arbitrary code execution in affected Red Hat Community Projects, such as `radare2` in EPEL and Fedora.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-0822 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2428463 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1846 Advisory
- https://github.com/quickjs-ng/quickjs/ product
- https://github.com/quickjs-ng/quickjs/commit/53eefbcd695165a3bd8c584813b472cb4a69fbf5 patch
- https://github.com/quickjs-ng/quickjs/issues/1297 issue-trackingExploitIssue TrackingVendor Advisory
- https://github.com/quickjs-ng/quickjs/issues/1297#issue-3780006202 exploitissue-trackingIssue TrackingVendor Advisory
- https://github.com/quickjs-ng/quickjs/pull/1298 issue-trackingIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-0822
- https://vuldb.com/?ctiid.340356 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.340356 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.731783 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2026-0822
Change history (0)
No recorded changes yet.