UBUNTU-CVE-2025-62492

Source
https://ubuntu.com/security/CVE-2025-62492
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62492.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-62492
Upstream
Published
2025-10-16T16:15:00Z
Modified
2026-05-20T16:23:39Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L CVSS Calculator
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied. * The fromIndex argument (read as a double variable, $d$) is used to calculate the starting position for the search. * If d is negative, the index is calculated relative to the end of the array by adding the array's length (len) to d: $$d_{new} = d + \text{len}$$ * Due to the inherent limitations of floating-point arithmetic, if the negative value $d$ is extremely small (e.g., $-1 \times 10^{-20}$), the addition $d + \text{len}$ can result in a loss of precision, yielding an outcome that is exactly equal to $\text{len}$. * The result is then converted to an integer index $k$: $k = \text{len}$. * The search function proceeds to read array elements starting from index $k$. Since valid indices are $0$ to $\text{len}-1$, starting the read at index $\text{len}$ is one element past the end of the array. This allows an attacker to cause an Out-of-Bounds Read of one element immediately following the buffer. While the scope of this read is small (one element), it can potentially lead to Information Disclosure of adjacent memory contents, depending on the execution environment.

References

Affected packages

Ubuntu:Pro:24.04:LTS / quickjs

Package

Name
quickjs
Purl
pkg:deb/ubuntu/quickjs?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2021.*
2021.03.27-1
2021.03.27-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libquickjs",
            "binary_version": "2021.03.27-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "quickjs",
            "binary_version": "2021.03.27-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62492.json"

Ubuntu:25.10 / quickjs

Package

Name
quickjs
Purl
pkg:deb/ubuntu/quickjs?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2024.*
2024.01.13-5
2025.*
2025.04.26-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libquickjs",
            "binary_version": "2025.04.26-1"
        },
        {
            "binary_name": "quickjs",
            "binary_version": "2025.04.26-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62492.json"

Ubuntu:26.04:LTS / quickjs

Package

Name
quickjs
Purl
pkg:deb/ubuntu/quickjs?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2025.*
2025.04.26-1
2025.04.26-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libquickjs",
            "binary_version": "2025.04.26-1build1"
        },
        {
            "binary_name": "quickjs",
            "binary_version": "2025.04.26-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62492.json"