UBUNTU-CVE-2026-40489

Source
https://ubuntu.com/security/CVE-2026-40489
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-40489
Upstream
Downstream
Related
Published
2026-04-20T00:00:00Z
Modified
2026-06-02T18:29:26Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ec_glob() that allows an attacker to crash any application using libeditorconfig by providing a specially crafted directory structure and .editorconfig file. This is an incomplete fix for CVE-2023-0341. The pcre_str buffer was protected in 0.12.6 but the adjacent l_pattern[8194] stack buffer received no equivalent protection. On Ubuntu 24.04, FORTIFY_SOURCE converts the overflow to SIGABRT (DoS). Version 0.12.11 contains an updated fix.

References

Affected packages

Ubuntu:24.04:LTS
editorconfig-core

Package

Name
editorconfig-core
Purl
pkg:deb/ubuntu/editorconfig-core?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.7-0.1ubuntu0.1

Affected versions

0.*
0.12.6-0.1
0.12.7-0.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "editorconfig",
            "binary_version": "0.12.7-0.1ubuntu0.1"
        },
        {
            "binary_name": "libeditorconfig0",
            "binary_version": "0.12.7-0.1ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json"
Ubuntu:25.10
editorconfig-core

Package

Name
editorconfig-core
Purl
pkg:deb/ubuntu/editorconfig-core?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.9+~0.17.1-1ubuntu2.1

Affected versions

0.*
0.12.9+~0.15.1-1ubuntu1
0.12.9+~0.17.1-1
0.12.9+~0.17.1-1ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "editorconfig",
            "binary_version": "0.12.9+~0.17.1-1ubuntu2.1"
        },
        {
            "binary_name": "libeditorconfig0",
            "binary_version": "0.12.9+~0.17.1-1ubuntu2.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json"
Ubuntu:26.04:LTS
editorconfig-core

Package

Name
editorconfig-core
Purl
pkg:deb/ubuntu/editorconfig-core?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.10+~0.17.1-3ubuntu0.1

Affected versions

0.*
0.12.9+~0.17.1-1ubuntu2
0.12.10+~0.17.1-2
0.12.10+~0.17.1-3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "editorconfig",
            "binary_version": "0.12.10+~0.17.1-3ubuntu0.1"
        },
        {
            "binary_name": "libeditorconfig0",
            "binary_version": "0.12.10+~0.17.1-3ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json"
Ubuntu:Pro:16.04:LTS
editorconfig-core

Package

Name
editorconfig-core
Purl
pkg:deb/ubuntu/editorconfig-core?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.0-2ubuntu0.1~esm3

Affected versions

0.*
0.12.0-2
0.12.0-2ubuntu0.1~esm1
0.12.0-2ubuntu0.1~esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "editorconfig",
            "binary_version": "0.12.0-2ubuntu0.1~esm3"
        },
        {
            "binary_name": "libeditorconfig0",
            "binary_version": "0.12.0-2ubuntu0.1~esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json"
Ubuntu:Pro:18.04:LTS
editorconfig-core

Package

Name
editorconfig-core
Purl
pkg:deb/ubuntu/editorconfig-core?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.1-1.1ubuntu0.18.04.1~esm3

Affected versions

0.*
0.12.1-1
0.12.1-1.1
0.12.1-1.1ubuntu0.18.04.1~esm1
0.12.1-1.1ubuntu0.18.04.1~esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "editorconfig",
            "binary_version": "0.12.1-1.1ubuntu0.18.04.1~esm3"
        },
        {
            "binary_name": "libeditorconfig0",
            "binary_version": "0.12.1-1.1ubuntu0.18.04.1~esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json"
Ubuntu:Pro:20.04:LTS
editorconfig-core

Package

Name
editorconfig-core
Purl
pkg:deb/ubuntu/editorconfig-core?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.1-1.1+deb11u1ubuntu0.1~esm1

Affected versions

0.*
0.12.1-1.1
0.12.1-1.1ubuntu0.20.04.1~esm1
0.12.1-1.1+deb11u1build0.20.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "editorconfig",
            "binary_version": "0.12.1-1.1+deb11u1ubuntu0.1~esm1"
        },
        {
            "binary_name": "libeditorconfig0",
            "binary_version": "0.12.1-1.1+deb11u1ubuntu0.1~esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json"
Ubuntu:Pro:22.04:LTS
editorconfig-core

Package

Name
editorconfig-core
Purl
pkg:deb/ubuntu/editorconfig-core?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.5-2ubuntu0.1~esm3

Affected versions

0.*
0.12.1-1.1
0.12.1-2
0.12.5-2
0.12.5-2ubuntu0.1~esm1
0.12.5-2ubuntu0.1~esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "editorconfig",
            "binary_version": "0.12.5-2ubuntu0.1~esm3"
        },
        {
            "binary_name": "libeditorconfig0",
            "binary_version": "0.12.5-2ubuntu0.1~esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40489.json"