3.3 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Exploit Code Maturity (E): Proof-of-Concept (P)
- Remediation Level (RL): Official Fix (O)
- Report Confidence (RC): Confirmed (C)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @anthonyroussel Activity log
- Created suggestion
-
@anthonyroussel
ignored
21 packages
- berry
- amiberry
- blueberry
- strawberry
- yarn-berry
- yarn-berry_3
- yarn-berry_4
- raspberrypifw
- libraspberrypi
- strawberry-qt6
- device-tree_rpi
- raspberrypi-eeprom
- raspberrypi-armstubs
- haskellPackages.huckleberry
- raspberrypiWirelessFirmware
- python312Packages.strawberry-django
- python313Packages.strawberry-django
- python312Packages.strawberry-graphql
- python313Packages.strawberry-graphql
- home-assistant-component-tests.raspberry_pi
- tests.home-assistant-component-tests.raspberry_pi
- @anthonyroussel dismissed
berry-lang berry be_lexer.c scan_string out-of-bounds
A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c59a39ba44feca261b12f06089f265fec176. Applying a patch is the recommended action to fix this issue.
References
-
-
-
Submit #758872 | berry-lang berry 7af8289 Buffer Overflow third-party-advisory
-
https://github.com/berry-lang/berry/issues/509 issue-tracking
-
Affected products
- ==1.0
- ==1.1.0
Ignored packages (21)
pkgs.berry
Healthy, bite-sized window manager
pkgs.amiberry
Optimized Amiga emulator for Linux/macOS
pkgs.blueberry
Bluetooth configuration tool
pkgs.strawberry
Music player and music collection organizer
pkgs.yarn-berry
Fast, reliable, and secure dependency management
pkgs.yarn-berry_3
Fast, reliable, and secure dependency management
pkgs.yarn-berry_4
Fast, reliable, and secure dependency management
pkgs.raspberrypifw
Firmware for the Raspberry Pi board
-
nixos-unstable 1.20250430
- nixpkgs-unstable 1.20250430
- nixos-unstable-small 1.20250430
pkgs.libraspberrypi
Userland tools & libraries for interfacing with Raspberry Pi hardware
-
nixos-unstable 0-unstable-2024-12-23
- nixpkgs-unstable 0-unstable-2024-12-23
- nixos-unstable-small 0-unstable-2024-12-23
pkgs.strawberry-qt6
None
pkgs.device-tree_rpi
DTBs for the Raspberry Pi
-
nixos-unstable 1.20250430
- nixpkgs-unstable 1.20250430
- nixos-unstable-small 1.20250430
pkgs.raspberrypi-eeprom
Installation scripts and binaries for the closed sourced Raspberry Pi 4 and 5 bootloader EEPROMs
-
nixos-unstable 2026.01.09-2711
- nixpkgs-unstable 2026.01.09-2711
- nixos-unstable-small 2026.01.09-2711
pkgs.raspberrypi-armstubs
Firmware related ARM stubs for the Raspberry Pi
-
nixos-unstable 2022-07-11
- nixpkgs-unstable 2022-07-11
- nixos-unstable-small 2022-07-11
pkgs.haskellPackages.huckleberry
Haskell IOT on Intel Edison and other Linux computers
pkgs.raspberrypiWirelessFirmware
Firmware for builtin Wifi/Bluetooth devices in the Raspberry Pi 3+ and Zero W
-
nixos-unstable 0-unstable-2025-04-08
- nixpkgs-unstable 0-unstable-2025-04-08
- nixos-unstable-small 0-unstable-2025-04-08
pkgs.python312Packages.strawberry-django
None
pkgs.python313Packages.strawberry-django
Strawberry GraphQL Django extension
pkgs.python312Packages.strawberry-graphql
None
pkgs.python313Packages.strawberry-graphql
GraphQL library for Python that leverages type annotations
pkgs.tests.home-assistant-component-tests.raspberry_pi
Open source home automation that puts local control and privacy first