PT-2023-12423 · Unknown · Serenityos

·

CVE-2021-4327

·

Published

2023-03-01

·

Updated

2024-05-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SerenityOS (affected versions not specified)
Description A critical issue has been found in SerenityOS, affecting the function initialize typed array from array buffer in the library Userland/Libraries/LibJS/Runtime/TypedArray.cpp. This issue leads to integer overflow. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, it is recommended to apply a patch, specifically the one identified as f6c6047e49f1517778f5565681fb64750b14bf60. As a temporary workaround, consider disabling the initialize typed array from array buffer function until the patch is applied.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-4327

Affected Products

Serenityos