First published: Thu Jun 10 2021(Updated: )
An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jerryscript Jerryscript | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26199 is classified as a critical vulnerability due to the potential for a heap-use-after-free condition, which can lead to arbitrary code execution.
To fix CVE-2021-26199, upgrade to a version of JerryScript that is higher than 2.4.0, as this vulnerability has been addressed in subsequent releases.
Exploitation of CVE-2021-26199 may result in application crashes, data corruption, or unauthorized access to sensitive information due to arbitrary code execution.
CVE-2021-26199 specifically affects JerryScript version 2.4.0.
CVE-2021-26199 is considered remotely exploitable, as attackers can leverage this vulnerability over the network to execute malicious code.