https://seclists.org/oss-sec/2026/q1/348: Off-by-one heap buffer overflow in libuv
Published Mar 19, 2026
·Updated
Affected Software
1 affected component
libuv libuv>=1.47.0
Frequently Asked Questions
1
What is the severity of CVE-2026-12345?
The severity of CVE-2026-12345 is considered medium due to the potential for exploitation causing application crashes or arbitrary code execution.
2
How do I fix CVE-2026-12345?
To fix CVE-2026-12345, upgrade to the latest version of libuv that addresses the off-by-one heap buffer overflow in the affected function.
3
What software is affected by CVE-2026-12345?
CVE-2026-12345 affects libuv, specifically when handling CJK characters in Windows console applications.
4
What vulnerabilities are similar to CVE-2026-12345?
Similar vulnerabilities to CVE-2026-12345 include other off-by-one and buffer overflow flaws in libraries that process user input.
5
What is the impact of CVE-2026-12345 on users?
The impact of CVE-2026-12345 on users includes potential application crashes and the risk of arbitrary code execution if exploited.