Description
A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c59a39ba44feca261b12f06089f265fec176. Applying a patch is the recommended action to fix this issue.
Problem types
Product status
1.1.0
Timeline
| 2026-02-26: | Advisory disclosed |
| 2026-02-26: | VulDB entry created |
| 2026-02-26: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.348014 (VDB-348014 | berry-lang berry be_lexer.c scan_string out-of-bounds)
vuldb.com/?ctiid.348014 (VDB-348014 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.758872 (Submit #758872 | berry-lang berry 7af8289 Buffer Overflow)
github.com/berry-lang/berry/issues/509
github.com/berry-lang/berry/pull/511
github.com/oneafter/0211/blob/main/be/repro
github.com/...ommit/7149c59a39ba44feca261b12f06089f265fec176
github.com/berry-lang/berry/