Home

Description

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

PUBLISHED Reserved 2026-04-10 | Published 2026-04-10 | Updated 2026-04-14 | Assigner mitre




HIGH: 8.1CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-670 Always-Incorrect Control Flow Implementation

Product status

Default status
unknown

0.7.10 (semver)
affected

References

www.openwall.com/lists/oss-security/2026/04/10/13

musl.libc.org/releases.html

www.openwall.com/lists/oss-security/2026/04/10/13

cve.org (CVE-2026-40200)

nvd.nist.gov (CVE-2026-40200)

Download JSON