Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-12216

Опубликовано: 15 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.3

Описание

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of the argument count_instr can lead to memory corruption. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

РелизСтатусПримечание
devel

deferred

2026-07-16
esm-apps/bionic

deferred

2026-07-16
esm-apps/focal

deferred

2026-07-16
esm-apps/jammy

deferred

2026-07-16
jammy

deferred

2026-07-16
noble

deferred

2026-07-16
questing

ignored

end of life, was deferred [2026-07-16]
resolute

deferred

2026-07-16
upstream

needs-triage

Показывать по

EPSS

Процентиль: 2%
0.00112
Низкий

4.3 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
2 месяца назад

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of the argument count_instr can lead to memory corruption. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
nvd
2 месяца назад

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of the argument count_instr can lead to memory corruption. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
debian
2 месяца назад

A weakness has been identified in svaarala duktape up to 2.99.99. This ...

CVSS3: 5.3
github
2 месяца назад

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of the argument count_instr can lead to memory corruption. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 2%
0.00112
Низкий

4.3 Medium

CVSS2

5.3 Medium

CVSS3