Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

x86-64 switch miscompilation can read beyond its jump table

COMPCERT-595

Affected product
CompCert
Severity
Unrated
Disclosed

Summary

CompCert 3.0 through 3.17 could use stale upper register bits as part of a jump-table index, causing a fault or an unintended jump. Fixed in CompCert 3.18. The public reproducer does not establish remote exploitation or reliable control of the destination; no severity or CVSS score is assigned upstream.

Technical analysis

The accompanying research article explains the finding, reproduction, and remediation status.

Read the technical write-up

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References