Bug 2430790 (CVE-2026-1145)

Summary: CVE-2026-1145 quickjs-ng: quickjs-ng quickjs: Heap-based buffer overflow leading to information disclosure or denial of service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in quickjs-ng quickjs. This vulnerability, a heap-based buffer overflow, exists in the `js_typed_array_constructor_ta` function. A remote attacker can exploit this by sending specially crafted input, which could lead to unauthorized information disclosure or system instability (denial of service).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2430800, 2430802, 2430804, 2430808, 2430806    
Bug Blocks:    

Description OSIDB Bzimport 2026-01-19 09:01:15 UTC
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 53aebe66170d545bb6265906fe4324e4477de8b4. It is suggested to install a patch to address this issue.