PT-2026-33581 · Editorconfig · Editorconfig-Core-C
Published
2026-04-18
·
Updated
2026-04-18
·
CVE-2026-40489
CVSS v4.0
8.6
High
| AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ec glob() that allows an attacker to crash any application using libeditorconfig by providing a specially crafted directory structure and .editorconfig file. This is an incomplete fix for CVE-2023-0341. The pcre str buffer was protected in 0.12.6 but the adjacent l pattern[8194] stack buffer received no equivalent protection. On Ubuntu 24.04, FORTIFY SOURCE converts the overflow to SIGABRT (DoS). Version 0.12.11 contains an updated fix.
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Editorconfig-Core-C