Alpine: quickjs-ng: security update to 0.11.0-r1

medium Tenable Cloud Security Plugin ID 446242

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function
js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer
overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be
utilized. This patch is called c5d80831e51e48a83eab16ea867be87f091783c5. A patch should be applied to
remediate this issue. (CVE-2026-0821)

- A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function
js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote
exploitation of the attack is possible. The exploit is publicly available and might be used. The
identifier of the patch is 53eefbcd695165a3bd8c584813b472cb4a69fbf5. To fix this issue, it is recommended
to deploy a patch. (CVE-2026-0822)

- A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the
file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The
attack can be executed remotely. The exploit is now public and may be used. The patch is identified as
ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.
(CVE-2026-1144)

- A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function
js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow.
The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch
name: 53aebe66170d545bb6265906fe4324e4477de8b4. It is suggested to install a patch to address this issue.
(CVE-2026-1145)

Solution

Update the quickjs-ng library and its related packages to version 0.11.0-r1 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-0821

https://security.alpinelinux.org/vuln/CVE-2026-0822

https://security.alpinelinux.org/vuln/CVE-2026-1144

https://security.alpinelinux.org/vuln/CVE-2026-1145

Plugin Details

Severity: Medium

ID: 446242

Version: Revision 1.1

Type: Local

Published: 8/23/2026

Updated: 8/23/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.45

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-1145

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-0821

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 5.5

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-0821

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 1/10/2026

Reference Information

CVE: CVE-2026-0821, CVE-2026-0822, CVE-2026-1144, CVE-2026-1145