Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service. | |
| Title | vm2 before 3.11.7 Memory Disclosure via Buffer Pool | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:47:14.117Z
Reserved: 2026-09-17T12:43:03.568Z
Link: CVE-2026-92947
Updated: 2026-09-17T15:47:06.803Z
Status : Deferred
Published: 2026-09-17T14:18:00.140
Modified: 2026-09-17T16:18:34.667
Link: CVE-2026-92947
No data.
OpenCVE Enrichment
No data.