CVE-2026-0821

Publication date 10 January 2026

Last updated 7 August 2026


Ubuntu priority

Cvss 3 Severity Score

7.3 · High

Score breakdown

Description

A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called c5d80831e51e48a83eab16ea867be87f091783c5. A patch should be applied to remediate this issue.

Status

Package Ubuntu Release Status
quickjs 26.04 LTS resolute
Vulnerable
25.10 questing Ignored end of life, was needed
25.04 plucky Ignored end of life, was needs-triage
24.04 LTS noble
Vulnerable
22.04 LTS jammy Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
quickjs

Severity score breakdown

CVSS version:

Base score 5.5 · Medium

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Base score 7.3 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L


Access our resources on patching vulnerabilities