VORANT. Threat Intelligence Sign in Get the full feed

8cc Compiler Out-of-Bounds Read Flaw Disclosed

low vulnerability

CERT Polska coordinated disclosure of CVE-2026-50643, an out-of-bounds read in the 8cc compiler caused by unvalidated #line directive handling.

CERT Polska has coordinated disclosure of a vulnerability in the 8cc C compiler, tracked as CVE-2026-50643. The flaw stems from improper handling of #line directives and GNU linemarkers, where attacker-controlled filename and line-number metadata is accepted and later used without validation when indexing into source line arrays. Supplying invalid or oversized line numbers can trigger an out-of-bounds memory read, leading to a crash.

The vulnerability was confirmed in the version corresponding to commit b480958; other versions were not tested but may also be affected. The maintainer was notified early in the process but did not respond with details on the vulnerable version range, limiting the scope of remediation guidance available to users. This is a low-severity, low-impact issue affecting a niche compiler project, with no evidence of active exploitation; the primary risk is denial of service (crash) rather than code execution.

The report credits Michal Majchrowicz and Marcin Wyczechowski of AFINE for responsible disclosure, coordinated through CERT Polska's standard CVD process.

Mentioned in this report

Vulnerabilities CVE-2026-50643

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-50643

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free