PT-2026-97863 · Tinyexr · Tinyexr

CVE-2026-88355

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions tinyexpr version 4a7456e
Description An incorrect buffer size calculation occurs in the new expr() function. For arity-0 expression nodes, such as constants, variables, and zero-argument functions, the function allocates less memory than the size of a te expr object but continues to treat the allocation as a complete te expr object. This leads to undefined behavior and can cause deterministic process termination in builds instrumented with UBSan (Undefined Behavior Sanitizer), a tool used to detect undefined behavior in C and C++ programs.
Recommendations As a temporary workaround, avoid using arity-0 expression nodes in the new expr() function until a fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-88355

Affected Products

Tinyexr