Description
A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is named 0f285855f0e34f9183956be5f16e045f54626bff. To fix this issue, it is recommended to deploy a patch.
Problem types
Product status
1.40.1
Timeline
| 2026-02-09: | Advisory disclosed |
| 2026-02-09: | VulDB entry created |
| 2026-02-09: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.344980 (VDB-344980 | janet-lang janet os.c os_strftime out-of-bounds)
vuldb.com/?ctiid.344980 (VDB-344980 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.753156 (Submit #753156 | janet-lang janet c43e066 Heap-based Buffer Overflow)
github.com/janet-lang/janet/issues/1701
github.com/janet-lang/janet/issues/1701
github.com/oneafter/0123/blob/main/ja3/repro
github.com/...ommit/0f285855f0e34f9183956be5f16e045f54626bff
github.com/janet-lang/janet/