CVE-2026-40447
Linux Red Hat vulnerability analysis and mitigation

Overview

CVE-2026-40447 is an integer overflow or wraparound vulnerability (CWE-190) in Samsung Open Source Escargot, a lightweight JavaScript engine. The vulnerability allows undefined behavior and can be exploited to cause a denial of service condition. It affects Escargot at commit 97e8115ab1110bc502b4b5e4a0c689a71520d335 (dated 2026-03-28). Disclosed on April 13, 2026, it carries a CVSS v3.1 base score of 7.5 (High) per NVD, though the GitHub Advisory Database and ENISA EUVD rate it at 5.1 (Moderate) using a local attack vector (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) within the Escargot JavaScript engine, where arithmetic operations on integer values can exceed the representable range, causing the value to wrap around to an unexpected small or negative number, leading to undefined behavior. The fix, merged via pull request #1554 on April 8, 2026, addressed multiple minor issues including buffer size validation in CodeCacheReader and input validation in Serializer::deserializeFrom, suggesting the overflow may be related to deserialization or code cache processing logic (GitHub PR #1554). The NVD CVSS vector indicates a network-based attack with no privileges or user interaction required, while the GitHub Advisory scores it as a local, high-complexity attack — indicating some ambiguity in the precise attack surface (GitHub Advisory).

Impact

The primary impact of this vulnerability is on availability: a successful exploit can crash applications or services that embed the Escargot JavaScript engine, resulting in a denial of service condition through integer wraparound. There is no impact on confidentiality or integrity based on the CVSS scoring. The scope is limited to the affected component, with no evidence of lateral movement potential or data exposure risk (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.013% (0.000130), placing it in a very low probability tier for near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).

Mitigation and workarounds

A patch is available via Samsung Escargot pull request #1554, merged on April 8, 2026, which addresses the integer overflow along with related input validation and buffer size checking issues. Organizations should update their Escargot dependency to a commit after f25f05f (post-PR #1554 merge into the master branch). Until patching is complete, restricting local access to systems running the vulnerable version is advised as a temporary measure (GitHub PR #1554, GitHub Advisory).

Community reactions

Red Hat's Product Security team tracked this vulnerability via Bugzilla (Bug 2457772) with medium priority and severity, indicating awareness within the Linux ecosystem where Escargot may be packaged. No significant public researcher commentary or media coverage has been identified beyond standard vulnerability database entries (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Red Hat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42170HIGH7.8
  • Linux Debian logoLinux Debian
  • gimp-help-browser
NoYesAug 08, 2026
CVE-2026-7867HIGH7.8
  • Linux Debian logoLinux Debian
  • udisks2-lsm
NoYesAug 06, 2026
CVE-2026-15816HIGH7.5
  • Linux Red Hat logoLinux Red Hat
  • dracut
NoNoAug 07, 2026
CVE-2026-19079MEDIUM4.4
  • Linux Debian logoLinux Debian
  • policycoreutils-dbus
NoNoAug 07, 2026
CVE-2026-61477LOW2.3
  • Linux Debian logoLinux Debian
  • libvirt-daemon-lock
NoNoAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management