Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40200

Опубликовано: 10 апр. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in musl libc. This stack-based memory corruption vulnerability occurs when the qsort function processes extremely large arrays due to incorrectly implemented double-word primitives. A local attacker could exploit this by providing a specially crafted, very large array, potentially leading to arbitrary code execution or a denial of service.

Отчет

AN IMPORTANT stack-based memory corruption flaw in musl libc's qsort function could lead to arbitrary code execution or denial of service. This vulnerability requires a local attacker to provide an extremely large, specially crafted array, exceeding millions of elements, making practical exploitation highly improbable in typical Red Hat environments.

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2457369musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort

EPSS

Процентиль: 2%
0.00014
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 дня назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

CVSS3: 8.1
nvd
5 дней назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

CVSS3: 8.1
debian
5 дней назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based ...

CVSS3: 8.1
github
5 дней назад

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

EPSS

Процентиль: 2%
0.00014
Низкий

7.8 High

CVSS3