CVE-2026-0822: quickjs-ng quickjs quickjs.c js_typed_array_sort heap-based overflow
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function jstypedarraysort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 53eefbcd695165a3bd8c584813b472cb4a69fbf5. To fix this issue, it is recommended to deploy a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0822?
CVE-2026-0822 is classified as a high-severity vulnerability due to its potential for remote exploitation leading to a heap-based buffer overflow.
How do I fix CVE-2026-0822?
To mitigate CVE-2026-0822, upgrade quickjs-ng to version 0.11.1 or later which addresses the vulnerability.
What is the impact of CVE-2026-0822?
The impact of CVE-2026-0822 includes possible remote code execution due to a heap-based buffer overflow.
Who is affected by CVE-2026-0822?
CVE-2026-0822 affects users and applications utilizing quickjs-ng versions up to 0.11.0.
Can CVE-2026-0822 be exploited remotely?
Yes, CVE-2026-0822 can be exploited remotely, making it a critical concern for affected systems.