UBUNTU-CVE-2026-56017

Source
https://ubuntu.com/security/CVE-2026-56017
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-56017
Upstream
  • CVE-2026-56017
Published
2026-06-30T00:00:00Z
Modified
2026-06-30T18:17:55.347783315Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. The regexp versus division disambiguator in JsTokenizeString (XS.xs) inspects the previous token's last byte to choose between a regexp literal and a division operator. When a slash is the first meaningful token, with the start of input or only whitespace and comments before it, there is no valid preceding token: the walk back over whitespace and comment nodes runs off the head of the node list to NULL, and the byte lookup reads through a NULL contents pointer at an underflowed length index. The following identifier check dereferences the same NULL pointer. The crash is reachable through the public minify() API, so input as small as a single slash byte crashes the calling process. A service that minifies untrusted or third-party JavaScript can be crashed by a remote request, causing denial of service.

References

Affected packages

Ubuntu:16.04:LTS
libjavascript-minifier-xs-perl

Package

Name
libjavascript-minifier-xs-perl
Purl
pkg:deb/ubuntu/libjavascript-minifier-xs-perl?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.11-1
0.11-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.11-1build1",
            "binary_name": "libjavascript-minifier-xs-perl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json"
Ubuntu:18.04:LTS
libjavascript-minifier-xs-perl

Package

Name
libjavascript-minifier-xs-perl
Purl
pkg:deb/ubuntu/libjavascript-minifier-xs-perl?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.11-1build3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libjavascript-minifier-xs-perl",
            "binary_version": "0.11-1build3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json"
Ubuntu:20.04:LTS
libjavascript-minifier-xs-perl

Package

Name
libjavascript-minifier-xs-perl
Purl
pkg:deb/ubuntu/libjavascript-minifier-xs-perl?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.11-1build4
0.11-1build5

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libjavascript-minifier-xs-perl",
            "binary_version": "0.11-1build5"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json"
Ubuntu:22.04:LTS
libjavascript-minifier-xs-perl

Package

Name
libjavascript-minifier-xs-perl
Purl
pkg:deb/ubuntu/libjavascript-minifier-xs-perl?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.13-1
0.15-1
0.15-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.15-1build1",
            "binary_name": "libjavascript-minifier-xs-perl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json"
Ubuntu:24.04:LTS
libjavascript-minifier-xs-perl

Package

Name
libjavascript-minifier-xs-perl
Purl
pkg:deb/ubuntu/libjavascript-minifier-xs-perl?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.15-1build2
0.15-1build3
0.15-1build4
0.15-1build5

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.15-1build5",
            "binary_name": "libjavascript-minifier-xs-perl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json"
Ubuntu:25.10
libjavascript-minifier-xs-perl

Package

Name
libjavascript-minifier-xs-perl
Purl
pkg:deb/ubuntu/libjavascript-minifier-xs-perl?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.15-1build6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libjavascript-minifier-xs-perl",
            "binary_version": "0.15-1build6"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json"
Ubuntu:26.04:LTS
libjavascript-minifier-xs-perl

Package

Name
libjavascript-minifier-xs-perl
Purl
pkg:deb/ubuntu/libjavascript-minifier-xs-perl?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.15-1build6

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.15-1build6",
            "binary_name": "libjavascript-minifier-xs-perl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-56017.json"