CNNVD-202602-1899 Information

CNNVD ID

CNNVD-202602-1899

CVE-2025-70083

  • CNNVD Published: 2026-02-11

Description (Chinese)

OpenSatKit是OpenSatKit开源的一个应用程序开发工具包。 OpenSatKit 2.2.1版本存在安全漏洞,该漏洞源于DirName字段的复制操作存在栈缓冲区溢出,可能导致覆盖相邻的栈内存。

Description (English)

OpenSatKit is an application development toolkit for OpenSatKit open source. Release 2.2.1 of OpenSatKit contains a security loophole that stems from the replicating operation of the DirName field, which may result in the spilling out of the stowage buffer, which may cover the adjacent stowage memory.

Vulnerability Type

其他

Affected Vendor

OpenSatKit

Published

2026-02-11

Last Modified

2026-02-24

References

https://gist.github.com/jonafk555 https://github.com/OpenSatKit/OpenSatKit https://github.com/OpenSatKit/OpenSatKit/releases/tag/v2.2.1 https://raw.githubusercontent.com/OpenSatKit/OpenSatKit/master/cfs/apps/filemgr/fsw/src/dir.c https://raw.githubusercontent.com/OpenSatKit/OpenSatKit/master/cfs/apps/filemgr/fsw/src/dir.c#:~:text=strcpy%28DirWithSep

Patch

https://github.com/OpenSatKit/OpenSatKit/releases

Share on: