在 Linux x86-64 平台上,三星开源项目 Escargot 中存在一个由数值截断导致的越界写入漏洞。能够执行 JavaScript 的攻击者可以通过构造一个类定义来利用该漏洞,该定义的实例初始化条目数量超过 UINT16_MAX,从而破坏原生内存并导致宿主进程崩溃。 受影响的 Escargot 版本:commit hash 5dc93606abd42b859045add05d704a038e197359。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Samsung Opensource | Escargot | 5dc93606abd42b859045add05d704a038e197359 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86313 | 7.8 HIGH | 三星Walrus缓冲区溢出漏洞 |
| CVE-2026-86314 | 6.2 MEDIUM | Samsung Walrus整数溢出导致拒绝服务 |
No comments yet