MEDIUM
berry-lang berry be_lexer.c scan_string out-of-bounds
Published Feb 27, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.22%
Description
A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c59a39ba44feca261b12f06089f265fec176. Applying a patch is the recommended action to fix this issue.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version 1.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Berry-Lang | Berry | n/a |
|
- 1.1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-8992 Advisory
- https://github.com/berry-lang/berry/ product
- https://github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176 patch
- https://github.com/berry-lang/berry/issues/509 issue-trackingExploitIssue Tracking
- https://github.com/berry-lang/berry/pull/511 issue-trackingpatchIssue Tracking
- https://github.com/oneafter/0211/blob/main/be/repro exploit
- https://vuldb.com/?ctiid.348014 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.348014 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.758872 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-8992 | Advisory | |
| https://github.com/berry-lang/berry/ | product | |
| https://github.com/berry-lang/berry/commit/7149c59a39ba44feca261b12f06089f265fec176 | patch | |
| https://github.com/berry-lang/berry/issues/509 | issue-trackingExploitIssue Tracking | |
| https://github.com/berry-lang/berry/pull/511 | issue-trackingpatchIssue Tracking | |
| https://github.com/oneafter/0211/blob/main/be/repro | exploit | |
| https://vuldb.com/?ctiid.348014 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.348014 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.758872 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 27, 2026
Updated Feb 27, 2026
Reserved Feb 26, 2026
Link CVE-2026-3285
CISA Vulnrichment
Updated Feb 27, 2026
ENISA EUVD
EUVD-2026-8992 Assigner VulDB
Published Feb 27, 2026
Updated Feb 27, 2026
Exploited since n/a
Link EUVD-2026-8992