{"id":"CVE-2026-86315","details":"An out-of-bounds write caused by numeric truncation  Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX.\n\n\n\nThis issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359.","modified":"2026-10-08T02:52:14.988710730Z","published":"2026-09-07T04:01:28.554Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86315.json","cna_assigner":"samsung.tv_appliance","cwe_ids":["CWE-197"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86315.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86315"},{"type":"FIX","url":"https://github.com/Samsung/escargot/pull/1660"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/samsung/escargot","events":[{"introduced":"5dc93606abd42b859045add05d704a038e197359"},{"last_affected":"5dc93606abd42b859045add05d704a038e197359"}]}],"versions":["5dc93606abd42b859045add05d704a038e197359"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86315.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}