*** This bug is a security vulnerability ***
Public security bug reported:
Copied from Debian:
The following vulnerability was published for duktape.
CVE-2026-12216[0]:
| A weakness has been identified in svaarala duktape up to 2.99.99.
| This issue affects some unknown processing of the file
| duk_api_bytecode.c. Executing a manipulation of the argument
| count_instr can lead to memory corruption. The attack requires local
| access. The exploit has been made available to the public and could
| be used for attacks. The vendor was contacted early about this
| disclosure but did not respond in any way.
** Affects: duktape (Ubuntu)
Importance: Undecided
Status: New
** Affects: duktape (Debian)
Importance: Unknown
Status: Unknown
** CVE added: https://cve.org/CVERecord?id=CVE-2026-12216
** Bug watch added: Debian Bug tracker #1140485
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140485
** Also affects: duktape (Debian) via
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140485
Importance: Unknown
Status: Unknown
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169131
Title:
duktape: CVE-2026-12216
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/duktape/+bug/2169131/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs