PT-2026-33581 · Unknown+2 · Editorconfig-Core-C+2

CVE-2026-40489

·

Published

2026-04-18

·

Updated

2026-07-02

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions editorconfig-core-c versions prior to 0.12.11
Description A stack-based buffer overflow exists in the ec glob() function. An attacker can cause a crash in any application using libeditorconfig by providing a specially crafted directory structure and .editorconfig file. This occurs because the l pattern[8194] stack buffer lacks adequate protection, whereas the pcre str buffer was previously secured.
Recommendations Update to version 0.12.11.

Exploit

Fix

DoS

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40489
GHSA-97XG-VRCQ-254H
OESA-2026-2258
OESA-2026-2259
OESA-2026-2260
OPENSUSE-SU-2026:10663-1
OPENSUSE-SU-2026:20966-1
SUSE-SU-2026:22125-1
SUSE-SU-2026:2731-1
USN-8238-1
USN-8238-2

Affected Products

Linuxmint
Ubuntu
Editorconfig-Core-C