emscripten-core / emscripten-core/musl

High severity CVE for musl (CVE-2026-40200)

Open
#6 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
7
Forks
5
PR merge metrics
No merged PRs in 30d

Description

There's stack corruption in qsort if it's called on giant arrays.
"The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical)."

https://nvd.nist.gov/vuln/detail/CVE-2026-40200

It's pretty easy to patch, but there's a PR to update musl to 1.2.6. Given how big the array needs to be, we might want to wait for that merge to patch this CVE.

Patch:
https://www.openwall.com/lists/musl/2026/04/10/3/1

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.