A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function jsiteratorconcat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3979.json",
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-416"
]
}"2026-08-12T16:23:57Z"
[
{
"digest": {
"function_hash": "230536989381960940336023691743095805747",
"length": 786.0
},
"signature_type": "Function",
"source": "https://github.com/quickjs-ng/quickjs/commit/daab4ad4bae4ef071ed0294618d6244e92def4cd",
"id": "CVE-2026-3979-1854d883",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "quickjs.c",
"function": "js_iterator_concat_return"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"301286445733633105478528541740594711863",
"85104619995533220958437685240232835921",
"221517156546039221881911438746365139834",
"118199334696509644070484373721389146586",
"228899262248462652499761738676445631239",
"50944739852877348565986046444610209575",
"96892545259203819775449922083888496111",
"314240493682393923678887479567467512933",
"214653219760447087888356191352120869268"
]
},
"signature_type": "Line",
"source": "https://github.com/quickjs-ng/quickjs/commit/daab4ad4bae4ef071ed0294618d6244e92def4cd",
"id": "CVE-2026-3979-a7b8e35f",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "quickjs.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3979.json"