OSV-2025-541

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/quickjs/OSV-2025-541.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-541
Published
2025-07-09T00:20:09.455729Z
Modified
2025-07-09T00:20:09.456170Z
Summary
Heap-buffer-overflow in js_create_function
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=430091578

Crash type: Heap-buffer-overflow READ 2
Crash state:
js_create_function
__JS_EvalInternal
JS_EvalObject
References

Affected packages

OSS-Fuzz / quickjs

Package

Name
quickjs
Purl
pkg:generic/quickjs

Affected ranges

Type
GIT
Repo
https://github.com/bellard/quickjs
Events

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

fixed_range
"20d2b404af65edc5d66ee6f11a59f930ea3d1b88:fa628f8c523ecac8ce560c081411e91fcaba2d20"
introduced_range
"4d9a27c578d20fc22f0f1a51ff3bfaf47798f30e:458c34d29d0d262f824ea1c0e01aa0e3790669da"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/quickjs/OSV-2025-541.yaml"