PT-2026-23742 · Debian+2 · Quickjs
Published
2026-03-06
·
Updated
2026-03-06
·
CVE-2025-69653
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
QuickJS versions prior to 2025-12-11
Description
A specially crafted JavaScript input can cause an internal assertion failure within QuickJS. This occurs in the
gc decref child function of the quickjs.c file when the QuickJS interpreter (qjs) is executed with the -m option. This results in an abnormal program termination (SIGABRT) during garbage collection, leading to a denial-of-service condition.Recommendations
Update to QuickJS version 2025-12-11 or later.
Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quickjs