Beveiligingsadvies

CVE-2026-29079

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-13 17:19:46
Laatst bijgewerkt 2026-03-16 17:05:28
Toegewezen door GitHub_M
CVSS-score 8.2
Status PUBLISHED

Beschrijving

Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.