Description
A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/core/specials.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called c43e06672cd9dacf2122c99f362120a17c34b391. It is advisable to implement a patch to correct this issue.
Problem types
Product status
1.40.1
Timeline
| 2026-02-09: | Advisory disclosed |
| 2026-02-09: | VulDB entry created |
| 2026-02-09: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.344981 (VDB-344981 | janet-lang janet specials.c janetc_if out-of-bounds)
vuldb.com/?ctiid.344981 (VDB-344981 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.754495 (Submit #754495 | janet-lang janet 2fabc80 Heap-based Buffer Overflow)
github.com/janet-lang/janet/issues/1700
github.com/janet-lang/janet/issues/1702
github.com/oneafter/0123/blob/main/ja2/repro
github.com/...ommit/c43e06672cd9dacf2122c99f362120a17c34b391
github.com/janet-lang/janet/