*** This bug is a security vulnerability ***

Public security bug reported:

Copied from Debian:

The following vulnerability was published for duktape.

CVE-2026-12216[0]:
| A weakness has been identified in svaarala duktape up to 2.99.99.
| This issue affects some unknown processing of the file
| duk_api_bytecode.c. Executing a manipulation of the argument
| count_instr can lead to memory corruption. The attack requires local
| access. The exploit has been made available to the public and could
| be used for attacks. The vendor was contacted early about this
| disclosure but did not respond in any way.

** Affects: duktape (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: duktape (Debian)
     Importance: Unknown
         Status: Unknown

** CVE added: https://cve.org/CVERecord?id=CVE-2026-12216

** Bug watch added: Debian Bug tracker #1140485
   https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140485

** Also affects: duktape (Debian) via
   https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140485
   Importance: Unknown
       Status: Unknown

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169131

Title:
  duktape: CVE-2026-12216

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/duktape/+bug/2169131/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to