Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrwv-475h-2439

Опубликовано: 10 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

EPSS

Процентиль: 2%
0.00014
Низкий

8.1 High

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 дня назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

CVSS3: 7.8
redhat
5 дней назад

A flaw was found in musl libc. This stack-based memory corruption vulnerability occurs when the `qsort` function processes extremely large arrays due to incorrectly implemented double-word primitives. A local attacker could exploit this by providing a specially crafted, very large array, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 8.1
nvd
5 дней назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

CVSS3: 8.1
debian
5 дней назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based ...

EPSS

Процентиль: 2%
0.00014
Низкий

8.1 High

CVSS3

Дефекты

CWE-670