QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.
CVSS Details
- CVSS 3.1 Base Score: 3.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade quickjs | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade libquickjs (Ubuntu Pro)Upgrade quickjs (Ubuntu Pro) | Apr 16, 2025 | Apr 23, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub