๐Ÿ” CVE Alert

CVE-2026-40200

HIGH 8.1
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
2th

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

CWE CWE-670
Vendor musl-libc
Product musl
Published Apr 10, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for musl-libc musl

Be the first to know when new high vulnerabilities affecting musl-libc musl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

musl-libc / musl
0.7.10 โ‰ค 1.2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
musl.libc.org: https://musl.libc.org/releases.html openwall.com: https://www.openwall.com/lists/oss-security/2026/04/10/13 openwall.com: http://www.openwall.com/lists/oss-security/2026/04/10/13