Untriaged
Permalink
CVE-2026-2240
3.3 LOW
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
Activity log
- Created suggestion
janet-lang janet compile.c janetc_pop_funcdef out-of-bounds
A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef of the file src/core/compile.c. Such manipulation leads to out-of-bounds read. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The name of the patch is 4dd08a4cdef5b1c42d9a2c19fc24412e97ef51d5. A patch should be applied to remediate this issue.
References
-
VDB-344979 | janet-lang janet compile.c janetc_pop_funcdef out-of-bounds vdb-entrytechnical-description
-
-
Submit #753155 | janet-lang janet 883dde4 Heap-based Buffer Overflow third-party-advisory
-
https://github.com/janet-lang/janet/issues/1702 issue-tracking
Affected products
janet
- ==1.40.0
- ==1.40.1
Matching in nixpkgs
pkgs.janet
Janet programming language
pkgs.vscode-extensions.janet-lang.vscode-janet
Janet language support for Visual Studio Code
-
nixos-unstable 0.25.6
- nixpkgs-unstable 0.0.7-unstable-2025-05-19
- nixos-unstable-small 0.0.7-unstable-2025-05-19
-
nixos-unstable -
- nixpkgs-unstable 0.0.0+rev=7e28cbf
- nixos-unstable-small 0.0.0+rev=7e28cbf
pkgs.python312Packages.tree-sitter-grammars.tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
-
nixos-unstable 0.25.6
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
-
nixos-unstable 0.25.6
- nixpkgs-unstable 0.0.7+unstable20250519
- nixos-unstable-small 0.0.7+unstable20250519
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
-
nixos-unstable -
- nixpkgs-unstable 0.0.7+unstable20250519
- nixos-unstable-small 0.0.7+unstable20250519
Package maintainers
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@andrewchambers Andrew Chambers <ac@acha.ninja>
-
@stepbrobd Yifei Sun <ysun@hey.com>
-
@mightyiam Shahar "Dawn" Or <mightyiampresence@gmail.com>
-
@adfaure Adrien Faure <adfaure@pm.me>
-
@A-jay98 Ali Jamadi <ali@jamadi.me>
-
@wackbyte wackbyte <wackbyte@pm.me>