Vulnerability Description
A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Marsman1996/pocs/tree/master/redox/CVE-2026-38640
- https://gitlab.redox-os.org/redox-os/relibc/-/issues/262
- https://gitlab.redox-os.org/redox-os/relibc/-/merge_requests/986
- https://gitlab.redox-os.org/redox-os/relibc/-/work_items/262
FAQ
What is CVE-2026-38640?
CVE-2026-38640 is a vulnerability with a CVSS score of 7.5 (HIGH). A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.
How severe is CVE-2026-38640?
CVE-2026-38640 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-38640?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.