CVE-2026-2661: Squirrel sqobject.h operator heap-based overflow
A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2661?
CVE-2026-2661 has a high severity rating due to its potential for causing a heap-based buffer overflow.
How do I fix CVE-2026-2661?
To fix CVE-2026-2661, update Squirrel to a version later than 3.2 that addresses the vulnerability.
What is the impact of exploiting CVE-2026-2661?
Exploiting CVE-2026-2661 can lead to arbitrary code execution due to the heap-based buffer overflow.
Who is affected by CVE-2026-2661?
CVE-2026-2661 affects all users of Squirrel up to version 3.2.
Is CVE-2026-2661 a remote or local vulnerability?
CVE-2026-2661 requires local access to exploit the vulnerability.