A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/FascinatedBox/lily/ | Product |
| https://github.com/FascinatedBox/lily/issues/382 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/oneafter/0122/blob/main/i382/repro.lily | Exploit |
| https://vuldb.com/?ctiid.348276 | Permissions Required VDB Entry |
| https://vuldb.com/?id.348276 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.761326 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2026-03-01 10:16
Updated : 2026-03-05 01:38
NVD link : CVE-2026-3390
Mitre link : CVE-2026-3390
CVE.ORG link : CVE-2026-3390
JSON object : View
Products Affected
lily-lang
- lily
