{"id":"CVE-2026-86315","title":"An out-of-bounds write caused by numeric truncation  Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…","summary":"An out-of-bounds write caused by numeric truncation  Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-197","CWE-787"],"vendor":"Samsung Opensource","product":"Escargot","affected":["Escargot 5dc93606abd42b859045add05d704a038e197359"],"published":"2026-09-07","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:09:50.263","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86315","references":[{"url":"https://github.com/Samsung/escargot/pull/1660","label":"PSIRT@samsung.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86315.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-86315"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2529280"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-86315"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86315"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00123,"epssPercentile":0.02415,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T14:53:36.881610Z"},"ingestedAt":"2026-09-08T15:33:26.974Z","slug":"CVE-2026-86315","body":"## Overview\n\nAn out-of-bounds write caused by numeric truncation  Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX.\n\n\n\nThis issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: OpenShift Lightspeed, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, … · no fix planned: OpenShift Lightspeed, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86315.json)","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}