CVE-2026-40200
published 2026-04-10CVE-2026-40200: An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly…
PriorityP341high8.1CVSS 3.1
AVLACHPRNUINSCCHIHAH
EPSS
0.13%
2.8th percentile
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| musl-libc | musl | 0.7.10 – 1.2.6 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
vendor_redhat·2026-04-10·CVSS 8.1
CVE-2026-40200 [HIGH] CWE-190 musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).
A flaw was found in musl libc. This stack-based memory corruption vulnerability occurs when the `qsort` function processes extremely large arrays due to incorrectly implemented double-word primitives. A local attacker could exploit this by providing a specially crafted, very large array, potentially leading to arbitrar
VulDB
musl libc up to 1.2.6 control flow (EUVD-2026-21496)
vuldb·2026-04-10·CVSS 8.1
CVE-2026-40200 [HIGH] musl libc up to 1.2.6 control flow (EUVD-2026-21496)
A vulnerability, which was classified as problematic, was found in musl libc up to 1.2.6. Affected by this vulnerability is an unknown functionality. The manipulation results in incorrect control flow.
This vulnerability is reported as CVE-2026-40200. The attack requires a local approach. No exploit exists.
GHSA
GHSA-qrwv-475h-2439: An issue was discovered in musl libc 0
ghsa_unreviewed·2026-04-10
CVE-2026-40200 [HIGH] CWE-670 GHSA-qrwv-475h-2439: An issue was discovered in musl libc 0
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40200 musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
bugzilla·2026-04-10·CVSS 8.1
CVE-2026-40200 [HIGH] CVE-2026-40200 musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
CVE-2026-40200 musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).
Bugzilla
CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [epel-all]
bugzilla·2026-04-10·CVSS 8.1
CVE-2026-40200 [HIGH] CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [epel-all]
CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [fedora-42]
bugzilla·2026-04-10·CVSS 8.1
CVE-2026-40200 [HIGH] CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [fedora-42]
CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [fedora-43]
bugzilla·2026-04-10·CVSS 8.1
CVE-2026-40200 [HIGH] CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [fedora-43]
CVE-2026-40200 python-pandas: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-04-10
Published