<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 13:00:20 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-62493 — Heap out-of-bounds read in js_bigint_to_string1 in QuickJS</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-62493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; QuickJS&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the QuickJS engine&amp;#39;s BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in turn leads to reading memory past the allocated BigInt structure.&lt;/p&gt;
&lt;p&gt;*  The function determines the number of characters (n_digits) needed for the string representation by calculating:&lt;/p&gt;
&lt;p&gt;$$ \\ \text{n\_digits} = (\text{n\_bits} + \text{log2\_radix} - 1) / \text{log2\_radix}$$&lt;/p&gt;
&lt;p&gt;$$$$This formula is off-by-one in certain edge cases when calculating the necessary memory limbs. For instance, a 127-bit BigInt using radix 32 (where $\text{log2\_radix}=5$) is calculated to need $\text{n\_digits}=26$.&lt;/p&gt;
&lt;p&gt;*  The maximum number of bits actually stored is $\text{n\_bits}=127$, which requires only two 64-bit limbs ($\text{JS\_LIMB\_BITS}=64$).&lt;/p&gt;
&lt;p&gt;*  The conversion loop iterates $\text{n\_digits}=26$ times, attempting to read 5 bits in each iteration, totaling $26 \times 5 = 130$ bits.&lt;/p&gt;
&lt;p&gt;*  In the final iterations of the loop, the code attempts to read data that spans two limbs:&lt;/p&gt;
&lt;p&gt;C&lt;/p&gt;
&lt;p&gt;c = (r-&amp;gt;tab[pos] &amp;gt;&amp;gt; shift) | (r-&amp;gt;tab[pos + 1] &amp;lt;&amp;lt; (JS_LIMB_BITS - shift));&lt;/p&gt;
&lt;p&gt;*  Since the BigInt was only allocated two limbs, the read operation for r-&amp;gt;tab[pos + 1] becomes an Out-of-Bounds Read when pos points to the last valid limb (e.g., $pos=1$).&lt;/p&gt;
&lt;p&gt;This vulnerability allows an attacker to cause the engine to read and process data from the memory immediately following the BigInt buffer. This can lead to Information Discl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; QuickJS&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the QuickJS engine&amp;#39;s BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in turn leads to reading memory past the allocated BigInt structure.&lt;/p&gt;
&lt;p&gt;*  The function determines the number of characters (n_digits) needed for the string representation by calculating:&lt;/p&gt;
&lt;p&gt;$$ \\ \text{n\_digits} = (\text{n\_bits} + \text{log2\_radix} - 1) / \text{log2\_radix}$$&lt;/p&gt;
&lt;p&gt;$$$$This formula is off-by-one in certain edge cases when calculating the necessary memory limbs. For instance, a 127-bit BigInt using radix 32 (where $\text{log2\_radix}=5$) is calculated to need $\text{n\_digits}=26$.&lt;/p&gt;
&lt;p&gt;*  The maximum number of bits actually stored is $\text{n\_bits}=127$, which requires only two 64-bit limbs ($\text{JS\_LIMB\_BITS}=64$).&lt;/p&gt;
&lt;p&gt;*  The conversion loop iterates $\text{n\_digits}=26$ times, attempting to read 5 bits in each iteration, totaling $26 \times 5 = 130$ bits.&lt;/p&gt;
&lt;p&gt;*  In the final iterations of the loop, the code attempts to read data that spans two limbs:&lt;/p&gt;
&lt;p&gt;C&lt;/p&gt;
&lt;p&gt;c = (r-&amp;gt;tab[pos] &amp;gt;&amp;gt; shift) | (r-&amp;gt;tab[pos + 1] &amp;lt;&amp;lt; (JS_LIMB_BITS - shift));&lt;/p&gt;
&lt;p&gt;*  Since the BigInt was only allocated two limbs, the read operation for r-&amp;gt;tab[pos + 1] becomes an Out-of-Bounds Read when pos points to the last valid limb (e.g., $pos=1$).&lt;/p&gt;
&lt;p&gt;This vulnerability allows an attacker to cause the engine to read and process data from the memory immediately following the BigInt buffer. This can lead to Information Discl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-62493</guid>
    </item>
  </channel>
</rss>
