CVE-2026-0822

Publication date 10 January 2026

Last updated 7 August 2026


Ubuntu priority

Cvss 3 Severity Score

6.3 · Medium

Score breakdown

Description

A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 53eefbcd695165a3bd8c584813b472cb4a69fbf5. To fix this issue, it is recommended to deploy a patch.

Status

Package Ubuntu Release Status
quickjs 26.04 LTS resolute
Vulnerable
25.10 questing Ignored end of life, was needed
25.04 plucky Ignored end of life, was needs-triage
24.04 LTS noble
Vulnerable
22.04 LTS jammy Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
quickjs

Severity score breakdown

CVSS version:

Base score 2.1 · Low

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Base score 6.3 · Medium

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L


Access our resources on patching vulnerabilities