Description


Panda3D versions up to and including 1.10.16 deploy-stub contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based directly on the attacker-controlled argc value without validation. Supplying a large number of command-line arguments can exhaust stack space and propagate uninitialized stack memory into Python interpreter initialization, resulting in a reliable crash and undefined behavior.

Related CPE's


Vulnerable

Weaknesses



CWE-457CWE-789


CWE-908

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

5.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-07T21:16:02.747Z

5 days ago

Last modified

2026-01-12T18:00:28.637Z

6 hours ago