Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34764

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 2.3
EPSS Низкий

Описание

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain conditions, the release() callback provided on a paint event texture can outlive its backing native state, and invoking it after that point dereferences freed memory in the main process, which may lead to a crash or memory corruption. Apps are only affected if they use offscreen rendering with webPreferences.offscreen: { useSharedTexture: true }. Apps that do not enable shared-texture offscreen rendering are not affected. To mitigate this issue, ensure texture.release() is called promptly after the texture has been consumed, before the texture object becomes unreachable. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.

A flaw was found in Electron, a framework for building desktop applications. This vulnerability, a use-after-free, affects applications that utilize offscreen rendering with GPU shared textures. Under specific conditions, a callback function can attempt to access memory that has already been released, leading to a crash or memory corruption. This issue specifically impacts applications configured with webPreferences.offscreen: { useSharedTexture: true }.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Fix deferred
Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Fix deferred
Red Hat Build of Podman Desktop - Tech Previewrhdesktop/rh-podman-desktop-ext-openshift-local-rhel10Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2455466Electron: Electron: Memory corruption or crash due to use-after-free in offscreen rendering with shared textures.

EPSS

Процентиль: 1%
0.001
Низкий

2.3 Low

CVSS3

Связанные уязвимости

CVSS3: 2.3
nvd
4 месяца назад

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain conditions, the release() callback provided on a paint event texture can outlive its backing native state, and invoking it after that point dereferences freed memory in the main process, which may lead to a crash or memory corruption. Apps are only affected if they use offscreen rendering with webPreferences.offscreen: { useSharedTexture: true }. Apps that do not enable shared-texture offscreen rendering are not affected. To mitigate this issue, ensure texture.release() is called promptly after the texture has been consumed, before the texture object becomes unreachable. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.

CVSS3: 2.3
debian
4 месяца назад

Electron is a framework for writing cross-platform desktop application ...

CVSS3: 2.3
github
4 месяца назад

Electron: Use-after-free in offscreen shared texture release() callback

EPSS

Процентиль: 1%
0.001
Низкий

2.3 Low

CVSS3

Уязвимость CVE-2026-34764