{"id":"UBUNTU-CVE-2025-62491","details":"A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts-\u003erejected_promise_list).   *  The function js_std_promise_rejection_check attempts to iterate over the rejected_promise_list to report unhandled rejections using a standard list loop.   *  The reason for a promise rejection is processed inside the loop, including calling js_std_dump_error1(ctx, rp-\u003ereason).   *  If the promise rejection reason is an Error object that defines a custom property getter (e.g., via Object.defineProperty), this getter is executed during the error dumping process.   *  The malicious custom getter can execute JavaScript code that calls catch() on the same rejected promise being processed.   *  Calling catch() internally triggers js_std_promise_rejection_tracker, which then removes and frees the current promise entry (JSRejectedPromiseEntry) from the rejected_promise_list.   *  Since the list iteration continues using the now-freed memory pointer (el), the subsequent loop access results in a Use-After-Free condition.","modified":"2026-05-20T16:23:39.138622326Z","published":"2025-10-16T16:15:00Z","upstream":["CVE-2025-62491"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-62491"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-62491"},{"type":"REPORT","url":"https://issuetracker.google.com/434195203"},{"type":"REPORT","url":"https://bellard.org/quickjs/Changelog"}],"affected":[{"package":{"name":"quickjs","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/quickjs?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2021.03.27-1","2021.03.27-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"libquickjs","binary_version":"2021.03.27-1ubuntu0.1~esm1"},{"binary_name":"quickjs","binary_version":"2021.03.27-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62491.json"}},{"package":{"name":"quickjs","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/quickjs?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.01.13-5","2025.04.26-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libquickjs","binary_version":"2025.04.26-1"},{"binary_name":"quickjs","binary_version":"2025.04.26-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62491.json"}},{"package":{"name":"quickjs","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/quickjs?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2025.04.26-1","2025.04.26-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libquickjs","binary_version":"2025.04.26-1build1"},{"binary_version":"2025.04.26-1build1","binary_name":"quickjs"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62491.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}