Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-50343

Опубликовано: 30 дек. 2025
Источник: debian

Описание

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libmatiofixed1.5.30-1experimentalpackage
libmatiofixed1.5.30-2package
libmationo-dsatrixiepackage
libmationo-dsabookwormpackage

Примечания

  • https://github.com/tbeu/matio/issues/275

  • Fixed by: https://github.com/tbeu/matio/commit/41b505410dafaa236b61b52c7910d4c4831404f2

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 месяца назад

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.

CVSS3: 9.8
nvd
около 1 месяца назад

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.

CVSS3: 9.8
github
около 1 месяца назад

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.