Stack-based buffer overflow in editorconfig-core-c - CVE-2026-40489
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in ec_glob() when processing a crafted directory structure and .editorconfig file. A remote attacker can trick the victim into opening a file in an attacker-controlled directory to cause a denial of service.
User interaction is required to open the file.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
editorconfig-core (Ubuntu package)
editorconfig-libs
editorconfig-devel
editorconfig-debugsource
editorconfig-debuginfo
editorconfig
libeditorconfig0
editorconfig-core-c-debugsource
libeditorconfig-devel
libeditorconfig0-debuginfo
libeditorconfig-devel-64bit
libeditorconfig0-64bit-debuginfo
libeditorconfig0-64bit
libeditorconfig-devel-32bit
libeditorconfig0-32bit-debuginfo
libeditorconfig0-32bit
How to mitigate CVE-2026-40489
editorconfig-core (Ubuntu package) - addressed in versions 0.12.0-2ubuntu0.1~esm3, 0.12.1-1.1ubuntu0.18.04.1~esm3, 0.12.1-1.1+deb11u1ubuntu0.1~esm1, 0.12.5-2ubuntu0.1~esm3, 0.12.7-0.1ubuntu0.1, 0.12.9+~0.17.1-1ubuntu2.1, 0.12.10+~0.17.1-3ubuntu0.1
editorconfig-libs - update to 0.12.6-3
editorconfig-devel - update to 0.12.6-3
editorconfig-debugsource - update to 0.12.6-3
editorconfig-debuginfo - update to 0.12.6-3
editorconfig - update to 0.12.6-3
libeditorconfig0 - update to 0.12.6-150600.3.6.1
editorconfig-debuginfo - update to 0.12.6-150600.3.6.1
editorconfig-core-c-debugsource - update to 0.12.6-150600.3.6.1
libeditorconfig-devel - update to 0.12.6-150600.3.6.1
editorconfig - update to 0.12.6-150600.3.6.1
libeditorconfig0-debuginfo - update to 0.12.6-150600.3.6.1
libeditorconfig-devel-64bit - update to 0.12.6-150600.3.6.1
libeditorconfig0-64bit-debuginfo - update to 0.12.6-150600.3.6.1
libeditorconfig0-64bit - update to 0.12.6-150600.3.6.1
libeditorconfig-devel-32bit - update to 0.12.6-150600.3.6.1
libeditorconfig0-32bit-debuginfo - update to 0.12.6-150600.3.6.1
libeditorconfig0-32bit - update to 0.12.6-150600.3.6.1
editorconfig - addressed in versions 0.12.11-1.el8, 0.12.11-1.el9, 0.12.11-1.fc42, 0.12.11-1.fc43, 0.12.11-1.fc44
External References
Related Security Bulletins
- Stack-based buffer overflow in editorconfig-core-c
- Ubuntu update for editorconfig-core
- openEuler 24.03 LTS SP1 update for editorconfig
- openEuler 24.03 LTS update for editorconfig
- openEuler 24.03 LTS SP3 update for editorconfig
- Fedora 44 update for editorconfig
- Fedora 43 update for editorconfig
- Fedora 42 update for editorconfig
- Fedora EPEL 9 update for editorconfig
- Fedora EPEL 8 update for editorconfig
- Ubuntu update for editorconfig-core
- SUSE update for editorconfig-core-c