Overview: 1 vulnerability

WSA Score Severity Issue Vulnerability type Scope Versions Fix Release date
WSA-2026-12 6.6
Stack buffer overflow when building a JOIN command with channel keys. Stack-based Buffer Overflow IRC 0.3.6 → 4.9.4 4.9.5

WSA-2026-12: [IRC] Stack buffer overflow when building a JOIN command with channel keys.

Vulnerability
CVE
Not available
CVSS vector
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H (detail)
CVSS score
6.6 / 10
Severity
medium
Vulnerability type
Stack-based Buffer Overflow (detail)
Scope
IRC
Affected versions
0.3.6 → 4.9.4
Fixed version
4.9.5 () - ChangeLog
Commits
Description
A stack buffer overflow happens when building a JOIN command with a lot of channel and keys.
Mitigation
There is no known mitigation.
The upgrade to the latest stable version is highly recommended.
Credit
The issue was discovered by Mohammed Arib (arib06).