CyberRota Analysis
AI-GeneratedA vulnerability exists in the memory allocation for arity-0 expression nodes in tinyexpr, where insufficient memory is allocated for the te_expr object, leading to undefined behavior. This flaw can result in deterministic process termination when using UBSan-instrumented builds. Developers and maintainers of applications utilizing tinyexpr should prioritize addressing this issue to prevent potential crashes and instability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned allocation as a complete te_expr object. This results in undefined behavior and can cause deterministic process termination in UBSan-instrumented builds.