PT-2026-33581 · Editorconfig · Editorconfig-Core-C

Published

2026-04-18

·

Updated

2026-04-18

·

CVE-2026-40489

CVSS v4.0

8.6

High

AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ec glob() that allows an attacker to crash any application using libeditorconfig by providing a specially crafted directory structure and .editorconfig file. This is an incomplete fix for CVE-2023-0341. The pcre str buffer was protected in 0.12.6 but the adjacent l pattern[8194] stack buffer received no equivalent protection. On Ubuntu 24.04, FORTIFY SOURCE converts the overflow to SIGABRT (DoS). Version 0.12.11 contains an updated fix.

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-40489

Affected Products

Editorconfig-Core-C