Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-53432

Опубликовано: 30 июн. 2026
Источник: debian
EPSS Низкий

Описание

fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and pattern length is 999 bytes, the product overflows. The Go runtime detects the invalid slice bounds and terminates the process immediately with a non-recoverable panic. This issue was fixed in version 0.73.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fzffixed0.73.1-1package

Примечания

  • Fixed by: https://github.com/junegunn/fzf/commit/ccedd064ca56921a4235219516b3d834f60e7b91 (v0.73.0)

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 15%
0.0024
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and pattern length is 999 bytes, the product overflows. The Go runtime detects the invalid slice bounds and terminates the process immediately with a non-recoverable panic. This issue was fixed in version 0.73.1.

CVSS3: 5
redhat
около 1 месяца назад

fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and pattern length is 999 bytes, the product overflows. The Go runtime detects the invalid slice bounds and terminates the process immediately with a non-recoverable panic. This issue was fixed in version 0.73.1.

CVSS3: 7.5
nvd
около 1 месяца назад

fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and pattern length is 999 bytes, the product overflows. The Go runtime detects the invalid slice bounds and terminates the process immediately with a non-recoverable panic. This issue was fixed in version 0.73.1.

CVSS3: 7.5
github
около 1 месяца назад

fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and pattern length is 999 bytes, the product overflows. The Go runtime detects the invalid slice bounds and terminates the process immediately with a non-recoverable panic. This issue was fixed in version 0.73.1.

EPSS

Процентиль: 15%
0.0024
Низкий