CVE-2026-8258: Squirrel sqstdstring.cpp validate_format stack-based overflow
A flaw has been found in Squirrel up to 3.2. Impacted is the function validateformat in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8258?
CVE-2026-8258 is classified as a high severity vulnerability due to its potential for stack-based buffer overflow.
How do I fix CVE-2026-8258?
To fix CVE-2026-8258, update Squirrel to a version later than 3.2 that addresses this vulnerability.
What impact does CVE-2026-8258 have on affected systems?
CVE-2026-8258 allows a local attacker to execute code through a stack-based buffer overflow.
Is CVE-2026-8258 exploitable remotely?
No, CVE-2026-8258 can only be exploited locally.
What functions are affected by CVE-2026-8258?
The vulnerability CVE-2026-8258 affects the validate_format function in the sqstdlib/sqstdstring.cpp library.