Bug 2483786 (CVE-2026-10267) - CVE-2026-10267 janet: Janet: Information disclosure due to an out-of-bounds read vulnerability.
Summary: CVE-2026-10267 janet: Janet: Information disclosure due to an out-of-bounds r...
Keywords:
Status: NEW
Alias: CVE-2026-10267
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2483793
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-01 17:08 UTC by Sandipan Roy
Modified: 2026-06-09 08:59 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2026-06-01 17:08:04 UTC
A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/core/debug.c. Performing a manipulation results in out-of-bounds read. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named ed17dd2c5913a23fb1107251e44a9410a3c30cf5.


Note You need to log in before you can comment on or make changes to this bug.