ThakeeNathees pocketlang pkByteBufferAddString memory corruption
Published Mar 12, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.16%
Description
A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. The affected element is the function pkByteBufferAddString. The manipulation of the argument length with the input 4294967290 results in memory corruption. The attack requires a local approach. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
- Version StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| ThakeeNathees | Pocketlang | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://github.com/ThakeeNathees/pocketlang/ exploitproduct
- https://github.com/ThakeeNathees/pocketlang/issues/302 exploitissue-tracking
- https://github.com/oneafter/0211/blob/main/po/repro exploit
- https://vuldb.com/?ctiid.350533 signaturepermissions-required
- https://vuldb.com/?id.350533 vdb-entrytechnical-description
- https://vuldb.com/?submit.769773 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/ThakeeNathees/pocketlang/ | exploitproduct | |
| https://github.com/ThakeeNathees/pocketlang/issues/302 | exploitissue-tracking | |
| https://github.com/oneafter/0211/blob/main/po/repro | exploit | |
| https://vuldb.com/?ctiid.350533 | signaturepermissions-required | |
| https://vuldb.com/?id.350533 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.769773 | third-party-advisory |
Change history (0)
No recorded changes yet.