Résumé
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Détails de l’avis
Impact
Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice.
Patches
The bug has been patched starting with version 6.2.9.
Références
Vulnérabilités liées
Tout Supply chain →- MEDIUMCVE-2026-59949
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
- MEDIUMGHSA-3gjw-f78c-vvpw
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
- HIGHCVE-2026-76905
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
- CRITICALCVE-2026-55211
surfio has an out-of-bounds read
- HIGHGHSA-jwjp-4649-v8jp
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
- MEDIUMCVE-2026-71498
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript