A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/FascinatedBox/lily/ | Product |
| https://github.com/FascinatedBox/lily/issues/382 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/oneafter/0122/blob/main/i382/repro.lily | Exploit |
| https://vuldb.com/?ctiid.348276 | Permissions Required VDB Entry |
| https://vuldb.com/?id.348276 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.761326 | Third Party Advisory VDB Entry |
Configurations
History
05 Mar 2026, 01:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/FascinatedBox/lily/ - Product | |
| References | () https://github.com/FascinatedBox/lily/issues/382 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/oneafter/0122/blob/main/i382/repro.lily - Exploit | |
| References | () https://vuldb.com/?ctiid.348276 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.348276 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.761326 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:lily-lang:lily:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| First Time |
Lily-lang
Lily-lang lily |
01 Mar 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-01 10:16
Updated : 2026-03-05 01:38
NVD link : CVE-2026-3390
Mitre link : CVE-2026-3390
CVE.ORG link : CVE-2026-3390
JSON object : View
Products Affected
lily-lang
- lily
