vulnerability
Ubuntu: USN-7439-1 (CVE-2023-48184): QuickJS vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
9 | (AV:N/AC:L/Au:N/C:N/I:C/A:C) | 2024-04-23 | 2025-04-16 | 2025-04-17 |
Severity
9
CVSS
(AV:N/AC:L/Au:N/C:N/I:C/A:C)
Published
2024-04-23
Added
2025-04-16
Modified
2025-04-17
Description
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.
Solution(s)
ubuntu-pro-upgrade-libquickjsubuntu-pro-upgrade-quickjs
References
- CVE-2023-48184
- https://attackerkb.com/topics/CVE-2023-48184
- UBUNTU-USN-7439-1
- URL-https://github.com/bellard/quickjs/commit/7414e5f67f9a404f3cf91ffa69d0c93bf46d099e
- URL-https://github.com/bellard/quickjs/issues/156
- URL-https://github.com/bellard/quickjs/issues/198
- URL-https://ubuntu.com/security/notices/USN-7439-1
- URL-https://www.cve.org/CVERecord?id=CVE-2023-48184

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.