<Vulnerability name="CVE-2026-54257">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-06-23T17:08:31</PublicDate>
    <Bugzilla id="2491877" url="https://bugzilla.redhat.com/show_bug.cgi?id=2491877" xml:lang="en:us">
electron: Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-131</CWE>
    <Details xml:lang="en:us" source="Mitre">
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation. This vulnerability is fixed in 42.3.3.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Electron, a framework for building cross-platform desktop applications. The Buffer implementation performs incorrect byte length calculations, resulting in a heap buffer underflow or overflow. An attacker could exploit this flaw to cause an application crash or trigger incorrect buffer allocations in the Node.js Buffer API, leading to unexpected data truncation or memory corruption, potentially allowing for arbitrary code execution.
    </Details>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:podman_desktop:1">
        <ProductName>Red Hat Build of Podman Desktop</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rh-podman-desktop.git</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-54257
https://nvd.nist.gov/vuln/detail/CVE-2026-54257
https://github.com/electron/electron/security/advisories/GHSA-q6m5-f73j-m9mc
    </References>
</Vulnerability>