Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54257

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation. This vulnerability is fixed in 42.3.3.

A flaw was found in Electron, a framework for building cross-platform desktop applications. The Buffer implementation performs incorrect byte length calculations, resulting in a heap buffer underflow or overflow. An attacker could exploit this flaw to cause an application crash or trigger incorrect buffer allocations in the Node.js Buffer API, leading to unexpected data truncation or memory corruption, potentially allowing for arbitrary code execution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2491877electron: Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

EPSS

Процентиль: 17%
0.00253
Низкий

7.1 High

CVSS3

Связанные уязвимости

nvd
около 1 месяца назад

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation. This vulnerability is fixed in 42.3.3.

debian
около 1 месяца назад

Electron is a framework for writing cross-platform desktop application ...

github
около 2 месяцев назад

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

EPSS

Процентиль: 17%
0.00253
Низкий

7.1 High

CVSS3