CVE-2025-46688

quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Configurations

No configuration.

History

28 Apr 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Las versiones quickjs-ng hasta la 0.9.0 tienen un cálculo de tamaño incorrecto en JS_ReadBigInt para un BigInt, lo que provoca un desbordamiento de búfer basado en el montón. Las versiones QuickJS anteriores al 26/04/2025 también se ven afectadas.
References () https://github.com/quickjs-ng/quickjs/issues/1018 - () https://github.com/quickjs-ng/quickjs/issues/1018 -

27 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-27 20:15

Updated : 2025-04-29 13:52


NVD link : CVE-2025-46688

Mitre link : CVE-2025-46688

CVE.ORG link : CVE-2025-46688


JSON object : View

Products Affected

No product.

CWE
CWE-131

Incorrect Calculation of Buffer Size