CNNVD-202511-2002 Information

CNNVD ID

CNNVD-202511-2002

CVE-2025-64076

  • CNNVD Published: 2025-11-18

Description (Chinese)

cbor2是Alex Grönholm个人开发者的一个具有广泛标签支持的二进制对象表示序列化格式编码和解码的库。 cbor2 5.7.0及之前版本存在安全漏洞,该漏洞源于decode_definite_long_string函数整数下溢和内存泄漏,可能导致越界读取和资源耗尽。

Description (English)

cbor2 is the library of an extensive labeled binary object from Alex Grönholm Personal Developer for serialized format code and decoded. Cbor2 5.7.0 and previous versions contain a security loophole, which originates from the spill down and leakage of the whole number of decode definite long string functions, which may lead to cross-border reading and depletion of resources.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

个人开发者

Published

2025-11-18

Last Modified

2026-02-24

References

https://github.com/agronholm/cbor2/commit/851473490281f82d82560b2368284ef33cf6e8f9 https://github.com/agronholm/cbor2/issues/264 https://github.com/agronholm/cbor2/pull/265 https://access.redhat.com/security/cve/cve-2025-64076

Patch

https://github.com/agronholm/cbor2/releases

Share on: