Source: duktape
Version: 2.7.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for duktape.

CVE-2026-12216[0]:
| A weakness has been identified in svaarala duktape up to 2.99.99.
| This issue affects some unknown processing of the file
| duk_api_bytecode.c. Executing a manipulation of the argument
| count_instr can lead to memory corruption. The attack requires local
| access. The exploit has been made available to the public and could
| be used for attacks. The vendor was contacted early about this
| disclosure but did not respond in any way.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-12216
    https://www.cve.org/CVERecord?id=CVE-2026-12216
[1] https://github.com/hmKunlun/compileOOB/blob/main/api_bytecode.md

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to