OSV-2025-884

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/quickjs/OSV-2025-884.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-884
Published
2025-11-08T00:17:46.632315Z
Modified
2025-11-08T00:17:46.633033Z
Summary
Heap-use-after-free in JS_DefineProperty
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=458199402

Crash type: Heap-use-after-free READ 8
Crash state:
JS_DefineProperty
build_backtrace
JS_CallInternal
References

Affected packages

OSS-Fuzz / quickjs

Package

Name
quickjs
Purl
pkg:generic/quickjs

Affected ranges

Type
GIT
Repo
https://github.com/bellard/quickjs
Events

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

fixed_range

"9688007ccbba2024b339ddcd52044b23e2a4d982:fcbf5ea2a63510f35f9ab2baadd59781be16a167"

introduced_range

"2d99c323a27ca9013230cfd6fb56ab37f2a0f1d4:8807fedec55bc4dbdf7b4780d36bfc4b4fd6e5e2"