GHSA-mc9m-6fm9-pghcMedium▾ SunlitZoo Design Studio: Memory-corruption in memory handling of lib-kcl
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A race condition in kcl-lib can result in a use-after-free when accessing environments concurrently. During Vec reallocation, the previous buffer containing Box pointers is freed and replaced. A concurrent get_env operation that has already loaded a pointer to the old buffer may subsequently index into freed memory and retrieve a stale or corrupted Pin<Box<Environment>>.
zoo-kcl < 0.3.153kcl-lib < 0.2.153Upgrade to a patched release:
zoo-kcl 0.3.153kcl-lib 0.2.153Connected by shared product, vendor, weakness, or advisory.
CVE-2026-43631High· 8.1llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary…
CVE-2023-35823High· 7.0An issue was discovered in the Linux kernel before 6.3.2
GHSA-jgvr-6x5w-hx5wMediumZoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
CVE-2026-26167High· 8.8Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26181High· 7.8Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-27921High· 7.0Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability