vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool
Published Sep 27, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.32%
Description
vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is the entire pool. Untrusted guest code can construct a full-width view of that ArrayBuffer (Buffer.from(result.buffer, 0, result.buffer.byteLength)) to read and modify bytes belonging to unrelated host buffers, disclosing and corrupting host-realm memory across the sandbox boundary.
Affected products
-
- Version 0StatusaffectedConstraints<3.12.2
- Version 3.12.2StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Patriksimek | Vm2 | unaffected |
|
No data.
No data.
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated as an Important severity because untrusted guest code can break sandbox isolation, allowing the disclosure and modification of host memory space. Exploitation requires an explicit, non-default configuration where the application grants the guest environment access to Node's builtin zlib compression module. Red Hat products shipping this library do not expose the vulnerable feature in their active execution paths, which prevents exposure under default configurations.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.32% (0.00316) | 22.24th | v5 (v2026.06.15) |
| Oct 1, 2026 | 0.32% (0.00316) | 22.16th | v5 (v2026.06.15) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-100723 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2542016 Issue Tracking
- https://github.com/patriksimek/vm2/commit/4f2508abeb252aa86eb6761c78b3b000248fb089 patch
- https://github.com/patriksimek/vm2/commit/5214b02ef13b82497fcb917b45320dfd014ffd09 patch
- https://github.com/patriksimek/vm2/security/advisories/GHSA-489w-w794-jq94 exploitvendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-100723
- https://www.cve.org/CVERecord?id=CVE-2026-100723
- https://www.vulncheck.com/advisories/vm2-before-3.12.2-memory-disclosure-via-zlib-buffer-pool third-party-advisory
Change history (0)
No recorded changes yet.