Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40200

Опубликовано: 10 апр. 2026
Источник: debian
EPSS Низкий

Описание

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
muslunfixedpackage
muslno-dsatrixiepackage
muslno-dsabookwormpackage
muslpostponedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/04/10/13

  • Fixed by: https://git.musl-libc.org/cgit/musl/commit/?id=228da39e38c1cae13cbe637e771412c1984dba5d

EPSS

Процентиль: 2%
0.00014
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 дня назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

CVSS3: 7.8
redhat
5 дней назад

A flaw was found in musl libc. This stack-based memory corruption vulnerability occurs when the `qsort` function processes extremely large arrays due to incorrectly implemented double-word primitives. A local attacker could exploit this by providing a specially crafted, very large array, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 8.1
nvd
5 дней назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

CVSS3: 8.1
github
5 дней назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

EPSS

Процентиль: 2%
0.00014
Низкий