Cyber News / Article / Vulnerability in 8cc compiler

Vulnerability in 8cc compiler
CERT Polska has received a report about vulnerability in 8cc compiler and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-50643: 8cc is vulnerable to an OutâofâBounds Read due to improper handling of#linedirectives and GNU linemarkers. The compiler accepts attacker-controlled filename and line number metadata and later uses it without validation when accessing source line arrays. By supplying invalid or oversized line numbers, an attacker can trigger out-of-bounds memory access and a crash.
Maintainer of this project was notified early about this vulnerability, but did not respond with the details of vulnerability or vulnerable version range. Version corresponding to the commit b480958 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
We thank Michal Majchrowicz and Marcin Wyczechowski (AFINE) for the responsible vulnerability report.
Related articles
Windows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote Code
2 days ago
Windows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely
2 days ago
New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server
2 days ago
You might Also like

Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

